2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5230 | HIGH | 7.5 | 1.2% | Jan 30, 2020 | Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be ... |
| CVE-2020-5222 | HIGH | 8.8 | 0.9% | Jan 30, 2020 | Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an add... |
| CVE-2020-5229 | HIGH | 8.1 | 0.6% | Jan 30, 2020 | Opencast before 8.1 stores passwords using the rather outdated and cryptographically insecure MD5 hash algorithm. Furthe... |
| CVE-2020-5228 | HIGH | 7.5 | 1.0% | Jan 30, 2020 | Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH ... |
| CVE-2020-8492 | MEDIUM | 6.5 | 6.6% | Jan 30, 2020 | Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTT... |
| CVE-2020-8093 | HIGH | 7.8 | 0.4% | Jan 30, 2020 | A vulnerability in the AntivirusforMac binary as used in Bitdefender Antivirus for Mac allows an attacker to inject a li... |
| CVE-2020-5233 | MEDIUM | 6.1 | 1.1% | Jan 30, 2020 | OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an atta... |
| CVE-2020-3147 | HIGH | 7.5 | 2.3% | Jan 30, 2020 | A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to cause ... |
| CVE-2020-8092 | MEDIUM | 5.5 | 0.3% | Jan 30, 2020 | A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to ob... |
| CVE-2020-7913 | MEDIUM | 6.1 | 1.1% | Jan 30, 2020 | JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description. |
| CVE-2020-7912 | MEDIUM | 5.3 | 1.5% | Jan 30, 2020 | In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups. |
| CVE-2020-7911 | MEDIUM | 6.1 | 0.6% | Jan 30, 2020 | In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS. |
| CVE-2020-7910 | MEDIUM | 5.4 | 0.5% | Jan 30, 2020 | JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role. |
| CVE-2020-7909 | HIGH | 7.5 | 1.1% | Jan 30, 2020 | In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI. |
| CVE-2020-7908 | MEDIUM | 4.3 | 0.8% | Jan 30, 2020 | In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages. |
| CVE-2020-7906 | HIGH | 7.5 | 0.7% | Jan 30, 2020 | In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows instal... |
| CVE-2020-7905 | HIGH | 7.5 | 1.2% | Jan 30, 2020 | Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network. |
| CVE-2020-7904 | HIGH | 7.4 | 1.4% | Jan 30, 2020 | In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS. |
| CVE-2020-1931 | HIGH | 8.1 | 6.5% | Jan 30, 2020 | A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.c... |
| CVE-2020-1930 | HIGH | 8.1 | 7.1% | Jan 30, 2020 | A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuratio... |
| CVE-2020-8448 | MEDIUM | 5.5 | 0.5% | Jan 30, 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a ... |
| CVE-2020-8447 | CRITICAL | 9.8 | 1.9% | Jan 30, 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a ... |
| CVE-2020-8446 | MEDIUM | 5.5 | 0.5% | Jan 30, 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to pa... |
| CVE-2020-8445 | CRITICAL | 9.8 | 2.3% | Jan 30, 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control c... |
| CVE-2020-8444 | CRITICAL | 9.8 | 2.5% | Jan 30, 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now