2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7964MEDIUM5.3An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutat...
CVE-2020-7052MEDIUM6.5CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a r...
CVE-2020-5224HIGH8.8In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessio...
CVE-2020-6966CRITICAL10In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center...
CVE-2020-6965CRITICAL9.9In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center...
CVE-2020-6964HIGH8.6In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center...
CVE-2020-6963CRITICAL10In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center...
CVE-2020-6962CRITICAL10In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Cente...
CVE-2020-6961CRITICAL10In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Cente...
CVE-2020-5219HIGH8.8Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userC...
CVE-2020-7226HIGH7.5CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excess...
CVE-2020-7245CRITICAL9.8Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arb...
CVE-2020-6007HIGH7.9Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handli...
CVE-2020-7941CRITICAL9.8A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some c...
CVE-2020-7940HIGH7.5Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to ...
CVE-2020-7939HIGH8.8SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. ...
CVE-2020-7938HIGH8.8plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up t...
CVE-2020-7937MEDIUM5.4An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScr...
CVE-2020-7936MEDIUM6.1An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a ...
CVE-2020-7220HIGH7.5HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount i...
CVE-2020-7931HIGH8.8In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modif...
CVE-2020-6843MEDIUM4.8Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-839...
CVE-2020-7210MEDIUM4.3Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
CVE-2020-5217MEDIUM5.8In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1...
CVE-2020-5216MEDIUM5.8In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now