2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4303MEDIUM6.1IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnera...
CVE-2020-11454MEDIUM5.4Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowin...
CVE-2020-11451HIGH7.2The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archiv...
CVE-2020-11450HIGH7.5Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information throu...
CVE-2020-11100HIGH8.8In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can w...
CVE-2020-8017MEDIUM6.3A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Ent...
CVE-2020-8016HIGH7A Race Condition Enabling Link Following vulnerability in the packaging of texlive-filesystem of SUSE Linux Enterprise M...
CVE-2020-11491MEDIUM4.9Monitoring::Logs in Zen Load Balancer 3.10.1 allows remote authenticated admins to conduct absolute path traversal attac...
CVE-2020-11490HIGH7.2Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via...
CVE-2020-11458MEDIUM4.9app/Model/feed.php in MISP before 2.4.124 allows administrators to choose arbitrary files that should be ingested by MIS...
CVE-2020-8015HIGH7.8A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attacke...
CVE-2020-1927MEDIUM6.1In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential m...
CVE-2020-8146HIGH7.8In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file del...
CVE-2020-8145MEDIUM6.5The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoint...
CVE-2020-8144HIGH8.4The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under cert...
CVE-2020-6096HIGH8.1An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calli...
CVE-2020-6009CRITICAL9.8LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.
CVE-2020-1958MEDIUM6.5When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials c...
CVE-2020-11470LOW3.3Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local pro...
CVE-2020-11469HIGH7.8Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during install...
CVE-2020-8966MEDIUM6.1There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages ...
CVE-2020-1954MEDIUM5.3Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If...
CVE-2020-11467HIGH7.2An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface...
CVE-2020-11466MEDIUM4.3An issue was discovered in Deskpro before 2019.8.0. The /api/tickets endpoint failed to properly validate a user's privi...
CVE-2020-11465HIGH8.8An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now