2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4673 | MEDIUM | 4.3 | 0.8% | Jan 12, 2021 | IBM Workload Automation 9.5 stores sensitive information in HTML comments that could aid in further attacks against the ... |
| CVE-2020-26713 | MEDIUM | 6.1 | 1.2% | Jan 12, 2021 | REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by th... |
| CVE-2020-25657 | MEDIUM | 5.9 | 1.7% | Jan 12, 2021 | A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the... |
| CVE-2020-35655 | MEDIUM | 5.4 | 1.5% | Jan 12, 2021 | In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because off... |
| CVE-2020-24701 | MEDIUM | 6.1 | 6.8% | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI). |
| CVE-2020-24700 | MEDIUM | 5.4 | 1.2% | Jan 12, 2021 | OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconf... |
| CVE-2020-23631 | MEDIUM | 6.1 | 0.5% | Jan 11, 2021 | Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-si... |
| CVE-2020-26298 | MEDIUM | 5.4 | 1.6% | Jan 11, 2021 | Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerabil... |
| CVE-2020-24025 | MEDIUM | 5.3 | 0.8% | Jan 11, 2021 | Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specify... |
| CVE-2020-4869 | MEDIUM | 6.5 | 1.8% | Jan 11, 2021 | IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflow. A remote attacker... |
| CVE-2020-25659 | MEDIUM | 5.9 | 2.5% | Jan 11, 2021 | python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing o... |
| CVE-2020-23849 | MEDIUM | 6.1 | 0.7% | Jan 11, 2021 | Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript. |
| CVE-2020-23644 | MEDIUM | 6.1 | 0.7% | Jan 11, 2021 | XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php. |
| CVE-2020-23643 | MEDIUM | 6.1 | 0.7% | Jan 11, 2021 | XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php. |
| CVE-2020-26800 | MEDIUM | 5.5 | 1.2% | Jan 11, 2021 | A stack overflow vulnerability in Aleth Ethereum C++ client version <= 1.8.0 using a specially crafted a config.json fil... |
| CVE-2020-13922 | MEDIUM | 6.5 | 1.7% | Jan 11, 2021 | Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users p... |
| CVE-2020-35727 | MEDIUM | 5.4 | 1.3% | Jan 11, 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ... |
| CVE-2020-35726 | MEDIUM | 6.1 | 1.6% | Jan 11, 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ... |
| CVE-2020-35725 | MEDIUM | 6.1 | 1.6% | Jan 11, 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ... |
| CVE-2020-35724 | MEDIUM | 5.4 | 1.2% | Jan 11, 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ... |
| CVE-2020-35723 | MEDIUM | 5.4 | 1.3% | Jan 11, 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ... |
| CVE-2020-35722 | MEDIUM | 6.5 | 0.7% | Jan 11, 2021 | CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/cr... |
| CVE-2020-35721 | MEDIUM | 5.4 | 1.3% | Jan 11, 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ... |
| CVE-2020-35720 | MEDIUM | 5.4 | 1.2% | Jan 11, 2021 | Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first... |
| CVE-2020-35719 | MEDIUM | 6.1 | 1.6% | Jan 11, 2021 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now