2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7964 | MEDIUM | 5.3 | 1.1% | Jan 24, 2020 | An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutat... |
| CVE-2020-7052 | MEDIUM | 6.5 | 1.9% | Jan 24, 2020 | CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a r... |
| CVE-2020-5224 | HIGH | 8.8 | 0.4% | Jan 24, 2020 | In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessio... |
| CVE-2020-6966 | CRITICAL | 10 | 2.2% | Jan 24, 2020 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center... |
| CVE-2020-6965 | CRITICAL | 9.9 | 1.1% | Jan 24, 2020 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center... |
| CVE-2020-6964 | HIGH | 8.6 | 1.4% | Jan 24, 2020 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center... |
| CVE-2020-6963 | CRITICAL | 10 | 2.7% | Jan 24, 2020 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center... |
| CVE-2020-6962 | CRITICAL | 10 | 4.9% | Jan 24, 2020 | In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Cente... |
| CVE-2020-6961 | CRITICAL | 10 | 1.6% | Jan 24, 2020 | In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Cente... |
| CVE-2020-5219 | HIGH | 8.8 | 2.4% | Jan 24, 2020 | Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userC... |
| CVE-2020-7226 | HIGH | 7.5 | 3.3% | Jan 24, 2020 | CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excess... |
| CVE-2020-7245 | CRITICAL | 9.8 | 1.2% | Jan 23, 2020 | Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arb... |
| CVE-2020-6007 | HIGH | 7.9 | 2.1% | Jan 23, 2020 | Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handli... |
| CVE-2020-7941 | CRITICAL | 9.8 | 2.3% | Jan 23, 2020 | A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some c... |
| CVE-2020-7940 | HIGH | 7.5 | 1.3% | Jan 23, 2020 | Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to ... |
| CVE-2020-7939 | HIGH | 8.8 | 1.2% | Jan 23, 2020 | SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. ... |
| CVE-2020-7938 | HIGH | 8.8 | 1.5% | Jan 23, 2020 | plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up t... |
| CVE-2020-7937 | MEDIUM | 5.4 | 0.8% | Jan 23, 2020 | An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScr... |
| CVE-2020-7936 | MEDIUM | 6.1 | 0.9% | Jan 23, 2020 | An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a ... |
| CVE-2020-7220 | HIGH | 7.5 | 1.4% | Jan 23, 2020 | HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount i... |
| CVE-2020-7931 | HIGH | 8.8 | 5.5% | Jan 23, 2020 | In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modif... |
| CVE-2020-6843 | MEDIUM | 4.8 | 2.4% | Jan 23, 2020 | Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-839... |
| CVE-2020-7210 | MEDIUM | 4.3 | 1.0% | Jan 23, 2020 | Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts. |
| CVE-2020-5217 | MEDIUM | 5.8 | 1.8% | Jan 23, 2020 | In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1... |
| CVE-2020-5216 | MEDIUM | 5.8 | 1.1% | Jan 23, 2020 | In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now