2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8514MEDIUM6.1An issue was discovered in Rumpus 8.2.10 on macOS. By crafting a directory name, it is possible to activate JavaScript i...
CVE-2020-8516MEDIUM5.3The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before att...
CVE-2020-8515CRITICAL9.8DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow...
CVE-2020-8512MEDIUM6.1In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.
CVE-2020-8505MEDIUM6.5School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.
CVE-2020-8504MEDIUM6.5School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrati...
CVE-2020-8503MEDIUM6.5Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object ...
CVE-2020-5234MEDIUM6.5MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS a...
CVE-2020-8422MEDIUM4.3An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 1...
CVE-2020-8440CRITICAL9.8controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by ...
CVE-2020-7956CRITICAL9.8HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates use...
CVE-2020-7955MEDIUM5.3HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resu...
CVE-2020-7914HIGH7.5In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over t...
CVE-2020-7219HIGH7.5HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were suscepti...
CVE-2020-7218HIGH7.5HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptib...
CVE-2020-5526MEDIUM5.9The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from server...
CVE-2020-5232HIGH8.7A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain ...
CVE-2020-8498MEDIUM5.4XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gist...
CVE-2020-8496MEDIUM4.8In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability b...
CVE-2020-8495HIGH7.5In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate se...
CVE-2020-8494HIGH8.8In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H402editUser se...
CVE-2020-8493MEDIUM4.8A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via...
CVE-2020-5231MEDIUM6.5In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new user...
CVE-2020-5206CRITICAL10In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume prope...
CVE-2020-8095MEDIUM5.5A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an at...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now