2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10255CRITICAL9Modern DRAM chips (DDR4 and LPDDR4 after 2015) are affected by a vulnerability in deployment of internal mitigations aga...
CVE-2020-4162MEDIUM5.4IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2020-10251MEDIUM5.5In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the ReadHEICImageByID function in coders\heic.c....
CVE-2020-10257CRITICAL9.8The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST...
CVE-2020-5342HIGH7.8Dell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability. A locally authe...
CVE-2020-9758CRITICAL9.6An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the ...
CVE-2020-10250CRITICAL9.8BWA DiREX-Pro 1.2181 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the PKG...
CVE-2020-10249MEDIUM5.3BWA DiREX-Pro 1.2181 devices allow full path disclosure via an invalid name array parameter to val_soft.php3.
CVE-2020-10248HIGH7.5BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwords via a direct request to val_users.php3.
CVE-2020-10247MEDIUM6.1MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_...
CVE-2020-10246MEDIUM6.1MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.
CVE-2020-10244HIGH7.5JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
CVE-2020-10192MEDIUM6.1An issue was discovered in Munkireport before 5.3.0.3923. An unauthenticated actor can send a custom XSS payload through...
CVE-2020-10191MEDIUM5.4An issue was discovered in MunkiReport before 5.3.0. An authenticated actor can send a custom XSS payload through the /m...
CVE-2020-10190HIGH8.8An issue was discovered in MunkiReport before 5.3.0. An authenticated user could achieve SQL Injection in app/models/tab...
CVE-2020-8987HIGH7.4Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate...
CVE-2020-4084MEDIUM5.4HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed ar...
CVE-2020-9517MEDIUM5.4There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Co...
CVE-2020-9386MEDIUM4.3In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed t...
CVE-2020-5256HIGH8.8BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, ...
CVE-2020-2159HIGH8.8Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands...
CVE-2020-2158HIGH8.8Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary typ...
CVE-2020-2157MEDIUM4.3Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configurat...
CVE-2020-2156MEDIUM4.3Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration ...
CVE-2020-2155MEDIUM5.3Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now