2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27459 | MEDIUM | 6.1 | 0.8% | Nov 16, 2020 | Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post. If any user sees the... |
| CVE-2020-25210 | MEDIUM | 5.3 | 1.4% | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants. |
| CVE-2020-7773 | MEDIUM | 6.1 | 1.3% | Nov 16, 2020 | This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of ... |
| CVE-2020-7765 | MEDIUM | 5.3 | 0.6% | Nov 16, 2020 | This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the D... |
| CVE-2020-5663 | MEDIUM | 5.4 | 0.7% | Nov 16, 2020 | Stored cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject ar... |
| CVE-2020-5662 | MEDIUM | 5.4 | 0.8% | Nov 16, 2020 | Reflected cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject... |
| CVE-2020-28656 | MEDIUM | 6.8 | 0.3% | Nov 16, 2020 | The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically pr... |
| CVE-2020-28650 | MEDIUM | 5.4 | 0.7% | Nov 16, 2020 | The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard W... |
| CVE-2020-8152 | MEDIUM | 4.4 | 0.3% | Nov 16, 2020 | Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the... |
| CVE-2020-6157 | MEDIUM | 4.3 | 0.7% | Nov 13, 2020 | Opera Touch for iOS before version 2.4.5 is vulnerable to an address bar spoofing attack. The vulnerability allows a mal... |
| CVE-2020-0599 | MEDIUM | 6.7 | 0.3% | Nov 13, 2020 | Improper access control in the PMC for some Intel(R) Processors may allow a privileged user to potentially enable escala... |
| CVE-2020-7962 | MEDIUM | 5.3 | 0.9% | Nov 13, 2020 | An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It i... |
| CVE-2020-26230 | MEDIUM | 5.3 | 1.6% | Nov 13, 2020 | Radar COVID is the official COVID-19 exposure notification app for Spain. In affected versions of Radar COVID, identific... |
| CVE-2020-26223 | MEDIUM | 6.5 | 1.1% | Nov 13, 2020 | Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versi... |
| CVE-2020-8582 | MEDIUM | 6.5 | 0.9% | Nov 13, 2020 | Element Software versions prior to 12.2 and HCI versions prior to 1.8P1 are susceptible to a vulnerability which could a... |
| CVE-2020-9129 | MEDIUM | 6.7 | 0.2% | Nov 13, 2020 | HUAWEI Mate 30 versions earlier than 10.1.0.159(C00E159R7P2) have a vulnerability of improper buffer operation. Due to i... |
| CVE-2020-9127 | MEDIUM | 6.7 | 0.4% | Nov 13, 2020 | Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high... |
| CVE-2020-26825 | MEDIUM | 6.1 | 0.6% | Nov 13, 2020 | SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use ... |
| CVE-2020-7032 | MEDIUM | 6.5 | 3.5% | Nov 13, 2020 | An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary f... |
| CVE-2020-7033 | MEDIUM | 5.4 | 0.6% | Nov 13, 2020 | A Cross Site Scripting (XSS) Vulnerability on the Unified Portal Client (web client) used in Avaya Equinox Conferencing ... |
| CVE-2020-27193 | MEDIUM | 6.1 | 2.0% | Nov 12, 2020 | A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run... |
| CVE-2020-17494 | MEDIUM | 5.3 | 0.8% | Nov 12, 2020 | Untangle Firewall NG before 16.0 uses MD5 for passwords. |
| CVE-2020-28415 | MEDIUM | 6.1 | 1.1% | Nov 12, 2020 | A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauth... |
| CVE-2020-28414 | MEDIUM | 6.1 | 1.1% | Nov 12, 2020 | A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauth... |
| CVE-2020-12926 | MEDIUM | 6.4 | 0.2% | Nov 12, 2020 | The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happe... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now