2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28208 | MEDIUM | 5.3 | 11.4% | Jan 8, 2021 | An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1. |
| CVE-2020-25678 | MEDIUM | 4.4 | 0.3% | Jan 8, 2021 | A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be f... |
| CVE-2020-27262 | MEDIUM | 5.4 | 0.7% | Jan 8, 2021 | Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 A stored cross-site scripting (XSS) vulnerability ex... |
| CVE-2020-27260 | MEDIUM | 5.3 | 0.4% | Jan 8, 2021 | Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affe... |
| CVE-2020-4667 | MEDIUM | 4.3 | 0.8% | Jan 8, 2021 | IBM Engineering Requirements Quality Assistant On-Premises could allow an authenticated user to obtain sensitive informa... |
| CVE-2020-4666 | MEDIUM | 5.4 | 0.6% | Jan 8, 2021 | IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability all... |
| CVE-2020-4664 | MEDIUM | 5.4 | 0.6% | Jan 8, 2021 | IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability all... |
| CVE-2020-4663 | MEDIUM | 5.4 | 0.6% | Jan 8, 2021 | IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability all... |
| CVE-2020-4606 | MEDIUM | 4.4 | 0.3% | Jan 8, 2021 | IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processin... |
| CVE-2020-25950 | MEDIUM | 4.3 | 0.4% | Jan 8, 2021 | Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact... |
| CVE-2020-4897 | MEDIUM | 5.3 | 1.6% | Jan 7, 2021 | IBM Emptoris Contract Management and IBM Emptoris Spend Analysis 10.1.0, 10.1.1, and 10.1.3 could allow a remote attacke... |
| CVE-2020-4896 | MEDIUM | 6.5 | 0.8% | Jan 7, 2021 | IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validati... |
| CVE-2020-4895 | MEDIUM | 5.4 | 0.6% | Jan 7, 2021 | IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This v... |
| CVE-2020-4893 | MEDIUM | 5.9 | 0.6% | Jan 7, 2021 | IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request ... |
| CVE-2020-4892 | MEDIUM | 5.4 | 0.6% | Jan 7, 2021 | IBM Emptoris Contract Management 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2020-27835 | MEDIUM | 4.4 | 0.3% | Jan 7, 2021 | A use after free in the Linux kernel infiniband hfi1 driver in versions prior to 5.10-rc6 was found in the way user call... |
| CVE-2020-25680 | MEDIUM | 5.4 | 0.3% | Jan 7, 2021 | A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore ... |
| CVE-2020-25476 | MEDIUM | 6.1 | 0.9% | Jan 7, 2021 | Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user ... |
| CVE-2020-35111 | MEDIUM | 4.3 | 1.2% | Jan 7, 2021 | When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not trigg... |
| CVE-2020-26979 | MEDIUM | 6.1 | 0.7% | Jan 7, 2021 | When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes ca... |
| CVE-2020-26978 | MEDIUM | 6.1 | 1.3% | Jan 7, 2021 | Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network'... |
| CVE-2020-26977 | MEDIUM | 6.5 | 0.9% | Jan 7, 2021 | By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab wh... |
| CVE-2020-26976 | MEDIUM | 6.5 | 1.6% | Jan 7, 2021 | When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service wo... |
| CVE-2020-26975 | MEDIUM | 6.5 | 0.9% | Jan 7, 2021 | When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary header... |
| CVE-2020-26768 | MEDIUM | 6.1 | 1.2% | Jan 7, 2021 | Formstone <=1.4.16 is vulnerable to a Reflected Cross-Site Scripting (XSS) vulnerability caused by improper validation o... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now