2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-29070MEDIUM4.8osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of n...
CVE-2020-26212MEDIUM6.5GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that ...
CVE-2020-25650MEDIUM5.5A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine...
CVE-2020-29072MEDIUM6.1A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires use...
CVE-2020-29069MEDIUM5.5_get_flag_ip_localdb in server/mhn/ui/utils.py in Modern Honey Network (MHN) through 2020-11-23 allows attackers to caus...
CVE-2020-26235MEDIUM5.3In Rust time crate from version 0.2.7 and before version 0.2.23, unix-like operating systems may segfault due to derefer...
CVE-2020-29055MEDIUM5.9An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 9716...
CVE-2020-26232MEDIUM5.4Jupyter Server before version 1.0.6 has an Open redirect vulnerability. A maliciously crafted link to a jupyter server c...
CVE-2020-29053MEDIUM6.1HRSALE 2.0.0 allows XSS via the admin/project/projects_calendar set_date parameter.
CVE-2020-28330MEDIUM6.5Barco wePresent WiPG-1600W devices have Unprotected Transport of Credentials. Affected Version(s): 2.5.1.8. An attacker ...
CVE-2020-25640MEDIUM5.3A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning lev...
CVE-2020-28928MEDIUM5.5In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source characte...
CVE-2020-28726MEDIUM6.1Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.
CVE-2020-24815MEDIUM6.5A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 ...
CVE-2020-10763MEDIUM5.5An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an...
CVE-2020-10762MEDIUM5.5An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block C...
CVE-2020-4003MEDIUM6.5VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulne...
CVE-2020-3984MEDIUM6.5The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which a...
CVE-2020-25474MEDIUM6.1SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Scripting (XSS) vulnerability via the editor_name p...
CVE-2020-25473MEDIUM6.5SimplePHPscripts News Script PHP Pro 2.3 does not properly set the HttpOnly Flag from Session Cookies.
CVE-2020-25472MEDIUM6.5SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows ...
CVE-2020-5641MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers...
CVE-2020-29003MEDIUM5.4The PollNY extension for MediaWiki through 1.35 allows XSS via an answer option for a poll question, entered during Spec...
CVE-2020-29002MEDIUM4.8includes/CologneBlueTemplate.php in the CologneBlue skin for MediaWiki through 1.35 allows XSS via a qbfind message supp...
CVE-2020-28348MEDIUM6.5HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not exp...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now