2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-28042MEDIUM5.3ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken functio...
CVE-2020-28041MEDIUM6.5The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate wi...
CVE-2020-28040MEDIUM4.3WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
CVE-2020-28038MEDIUM6.1WordPress before 5.5.2 allows stored XSS via post slugs.
CVE-2020-28034MEDIUM6.1WordPress before 5.5.2 allows XSS associated with global variables.
CVE-2020-28031MEDIUM4.3eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenti...
CVE-2020-28002MEDIUM5.3In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty val...
CVE-2020-27982MEDIUM6.1IceWarp 11.4.5.0 allows XSS via the language parameter.
CVE-2020-27359MEDIUM5.4A cross-site scripting (XSS) issue in REDCap 8.11.6 through 9.x before 10 allows attackers to inject arbitrary JavaScrip...
CVE-2020-27358MEDIUM4.3An issue was discovered in REDCap 8.11.6 through 9.x before 10. The messenger's CSV feature (that allows users to export...
CVE-2020-25689MEDIUM6.5A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in ...
CVE-2020-15914MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allo...
CVE-2020-27015MEDIUM4.4Trend Micro Antivirus for Mac 2020 (Consumer) contains an Error Message Information Disclosure vulnerability that if exp...
CVE-2020-27014MEDIUM6.4Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Block...
CVE-2020-27885MEDIUM6.1Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability t...
CVE-2020-26205MEDIUM5.4Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal throug...
CVE-2020-14323MEDIUM5.5A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and befor...
CVE-2020-27747MEDIUM6.8An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a...
CVE-2020-5935MEDIUM5.9On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0-15.1.0.5, 14.1.0-14....
CVE-2020-5934MEDIUM6.5On BIG-IP APM 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when multiple HTTP requests from the same client to...
CVE-2020-5932MEDIUM4.8On BIG-IP ASM 15.1.0-15.1.0.5, a cross-site scripting (XSS) vulnerability exists in the BIG-IP ASM Configuration utility...
CVE-2020-4864MEDIUM4.3IBM Resilient SOAR V38.0 could allow an attacker on the internal net work to provide the server with a spoofed source IP...
CVE-2020-27993MEDIUM5.3Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files.
CVE-2020-5938MEDIUM6.5On BIG-IP 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when negotiating IPSec tunnels with configured, authent...
CVE-2020-21266MEDIUM6.1Broadleaf Commerce 5.1.14-GA is affected by cross-site scripting (XSS) due to a slow HTTP post vulnerability.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now