2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-19668MEDIUM6.5Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6...
CVE-2020-4788MEDIUM4.7IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the dat...
CVE-2020-7573MEDIUM6.5A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that cou...
CVE-2020-7571MEDIUM5.4A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerabi...
CVE-2020-7570MEDIUM5.4A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists ...
CVE-2020-7568MEDIUM4.3A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon M221 (all referenc...
CVE-2020-7567MEDIUM5.7A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that...
CVE-2020-28954MEDIUM5.3web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrate...
CVE-2020-28953MEDIUM4.3In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.
CVE-2020-28350MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in OPAC in Sokrates SOWA SowaSQL through 5.6.1 via the sowacgi.php typ...
CVE-2020-28210MEDIUM6.1A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoS...
CVE-2020-28941MEDIUM5.5An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers ...
CVE-2020-28947MEDIUM6.1In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.
CVE-2020-22394MEDIUM6.1In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability.
CVE-2020-12496MEDIUM6.5Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45...
CVE-2020-28942MEDIUM4.3An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protoc...
CVE-2020-25703MEDIUM5.3The participants table download in Moodle always included user emails, but should have only done so when users' emails a...
CVE-2020-25702MEDIUM6.1In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. Thi...
CVE-2020-25701MEDIUM5.3If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabl...
CVE-2020-25700MEDIUM6.5In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versi...
CVE-2020-9049MEDIUM5.3A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could ...
CVE-2020-4718MEDIUM5.4IBM Jazz Reporting Service 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to stored cross-site scripting. This vulnerabili...
CVE-2020-15710MEDIUM6.1Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. ...
CVE-2020-8278MEDIUM5.3Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.
CVE-2020-5947MEDIUM4.3In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequenc...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now