2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28401 | MEDIUM | 6.5 | 1.3% | Jan 29, 2021 | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori... |
| CVE-2020-8585 | MEDIUM | 5.5 | 0.4% | Jan 28, 2021 | OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorize... |
| CVE-2020-36115 | MEDIUM | 5.4 | 0.6% | Jan 28, 2021 | Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf ... |
| CVE-2020-1725 | MEDIUM | 5.4 | 0.7% | Jan 28, 2021 | A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changi... |
| CVE-2020-1723 | MEDIUM | 6.1 | 1.0% | Jan 28, 2021 | A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbi... |
| CVE-2020-26272 | MEDIUM | 6.5 | 1.8% | Jan 28, 2021 | The Electron framework lets users write cross-platform desktop applications using JavaScript, HTML and CSS. In versions ... |
| CVE-2020-5428 | MEDIUM | 6 | 0.5% | Jan 27, 2021 | In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising cert... |
| CVE-2020-4865 | MEDIUM | 5.4 | 0.7% | Jan 27, 2021 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J... |
| CVE-2020-4855 | MEDIUM | 5.4 | 0.7% | Jan 27, 2021 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J... |
| CVE-2020-4789 | MEDIUM | 6.5 | 2.6% | Jan 27, 2021 | IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 could allow a remote attac... |
| CVE-2020-4786 | MEDIUM | 4.3 | 0.5% | Jan 27, 2021 | IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vulnerable to server si... |
| CVE-2020-4547 | MEDIUM | 5.4 | 0.8% | Jan 27, 2021 | IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a ... |
| CVE-2020-4524 | MEDIUM | 5.4 | 0.7% | Jan 27, 2021 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J... |
| CVE-2020-4189 | MEDIUM | 4.3 | 0.6% | Jan 27, 2021 | IBM Security Guardium 11.2 discloses sensitive information in the response headers that could be used in further attacks... |
| CVE-2020-4967 | MEDIUM | 4.3 | 0.7% | Jan 27, 2021 | IBM Cloud Pak for Security (CP4S) 1.3.0.1 could disclose sensitive information through HTTP headers which could be used ... |
| CVE-2020-4820 | MEDIUM | 6.1 | 0.7% | Jan 27, 2021 | IBM Cloud Pak for Security (CP4S) 1.4.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2020-4816 | MEDIUM | 5.9 | 1.2% | Jan 27, 2021 | IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the f... |
| CVE-2020-4815 | MEDIUM | 5.3 | 1.3% | Jan 27, 2021 | IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote user to obtain sensitive information from HTTP response h... |
| CVE-2020-4628 | MEDIUM | 5.3 | 1.3% | Jan 27, 2021 | IBM Cloud Pak for Security (CP4S) 1.3.0.1 and 1.4.0.0 could allow a remote attacker to obtain sensitive information when... |
| CVE-2020-36012 | MEDIUM | 4.8 | 0.7% | Jan 27, 2021 | Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary ... |
| CVE-2020-23774 | MEDIUM | 6.1 | 0.6% | Jan 26, 2021 | A reflected XSS vulnerability exists in tohtml/convert.php of Winmail 6.5, which can cause JavaScript code to be execute... |
| CVE-2020-8293 | MEDIUM | 6.5 | 1.6% | Jan 26, 2021 | A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in wo... |
| CVE-2020-8292 | MEDIUM | 5.4 | 0.9% | Jan 26, 2021 | Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop fun... |
| CVE-2020-8288 | MEDIUM | 5.4 | 0.8% | Jan 26, 2021 | The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability... |
| CVE-2020-6780 | MEDIUM | 4.9 | 0.6% | Jan 26, 2021 | Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now