2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8514 | MEDIUM | 6.1 | 0.8% | Feb 2, 2020 | An issue was discovered in Rumpus 8.2.10 on macOS. By crafting a directory name, it is possible to activate JavaScript i... |
| CVE-2020-8516 | MEDIUM | 5.3 | 2.6% | Feb 2, 2020 | The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before att... |
| CVE-2020-8515 | CRITICAL | 9.8 | 100.0% | Feb 1, 2020 | DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow... |
| CVE-2020-8512 | MEDIUM | 6.1 | 14.8% | Feb 1, 2020 | In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter. |
| CVE-2020-8505 | MEDIUM | 6.5 | 1.1% | Jan 31, 2020 | School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user. |
| CVE-2020-8504 | MEDIUM | 6.5 | 1.1% | Jan 31, 2020 | School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrati... |
| CVE-2020-8503 | MEDIUM | 6.5 | 0.7% | Jan 31, 2020 | Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object ... |
| CVE-2020-5234 | MEDIUM | 6.5 | 1.6% | Jan 31, 2020 | MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS a... |
| CVE-2020-8422 | MEDIUM | 4.3 | 1.2% | Jan 31, 2020 | An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 1... |
| CVE-2020-8440 | CRITICAL | 9.8 | 2.8% | Jan 31, 2020 | controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by ... |
| CVE-2020-7956 | CRITICAL | 9.8 | 1.0% | Jan 31, 2020 | HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates use... |
| CVE-2020-7955 | MEDIUM | 5.3 | 1.4% | Jan 31, 2020 | HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resu... |
| CVE-2020-7914 | HIGH | 7.5 | 1.9% | Jan 31, 2020 | In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over t... |
| CVE-2020-7219 | HIGH | 7.5 | 2.0% | Jan 31, 2020 | HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were suscepti... |
| CVE-2020-7218 | HIGH | 7.5 | 1.5% | Jan 31, 2020 | HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptib... |
| CVE-2020-5526 | MEDIUM | 5.9 | 0.5% | Jan 31, 2020 | The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from server... |
| CVE-2020-5232 | HIGH | 8.7 | 1.2% | Jan 31, 2020 | A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain ... |
| CVE-2020-8498 | MEDIUM | 5.4 | 1.2% | Jan 30, 2020 | XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gist... |
| CVE-2020-8496 | MEDIUM | 4.8 | 0.5% | Jan 30, 2020 | In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability b... |
| CVE-2020-8495 | HIGH | 7.5 | 3.1% | Jan 30, 2020 | In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate se... |
| CVE-2020-8494 | HIGH | 8.8 | 1.1% | Jan 30, 2020 | In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H402editUser se... |
| CVE-2020-8493 | MEDIUM | 4.8 | 1.5% | Jan 30, 2020 | A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via... |
| CVE-2020-5231 | MEDIUM | 6.5 | 0.6% | Jan 30, 2020 | In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new user... |
| CVE-2020-5206 | CRITICAL | 10 | 1.3% | Jan 30, 2020 | In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume prope... |
| CVE-2020-8095 | MEDIUM | 5.5 | 0.5% | Jan 30, 2020 | A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an at... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now