2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-27459MEDIUM6.1Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post. If any user sees the...
CVE-2020-25210MEDIUM5.3In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.
CVE-2020-7773MEDIUM6.1This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of ...
CVE-2020-7765MEDIUM5.3This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the D...
CVE-2020-5663MEDIUM5.4Stored cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject ar...
CVE-2020-5662MEDIUM5.4Reflected cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject...
CVE-2020-28656MEDIUM6.8The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically pr...
CVE-2020-28650MEDIUM5.4The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard W...
CVE-2020-8152MEDIUM4.4Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the...
CVE-2020-6157MEDIUM4.3Opera Touch for iOS before version 2.4.5 is vulnerable to an address bar spoofing attack. The vulnerability allows a mal...
CVE-2020-0599MEDIUM6.7Improper access control in the PMC for some Intel(R) Processors may allow a privileged user to potentially enable escala...
CVE-2020-7962MEDIUM5.3An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It i...
CVE-2020-26230MEDIUM5.3Radar COVID is the official COVID-19 exposure notification app for Spain. In affected versions of Radar COVID, identific...
CVE-2020-26223MEDIUM6.5Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versi...
CVE-2020-8582MEDIUM6.5Element Software versions prior to 12.2 and HCI versions prior to 1.8P1 are susceptible to a vulnerability which could a...
CVE-2020-9129MEDIUM6.7HUAWEI Mate 30 versions earlier than 10.1.0.159(C00E159R7P2) have a vulnerability of improper buffer operation. Due to i...
CVE-2020-9127MEDIUM6.7Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high...
CVE-2020-26825MEDIUM6.1SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use ...
CVE-2020-7032MEDIUM6.5An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary f...
CVE-2020-7033MEDIUM5.4A Cross Site Scripting (XSS) Vulnerability on the Unified Portal Client (web client) used in Avaya Equinox Conferencing ...
CVE-2020-27193MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run...
CVE-2020-17494MEDIUM5.3Untangle Firewall NG before 16.0 uses MD5 for passwords.
CVE-2020-28415MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauth...
CVE-2020-28414MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauth...
CVE-2020-12926MEDIUM6.4The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happe...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now