2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-25516MEDIUM5.4WSO2 Enterprise Integrator 6.6.0 or earlier contains a stored cross-site scripting (XSS) vulnerability in BPMN explorer ...
CVE-2020-27658MEDIUM6.1Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the sessio...
CVE-2020-27657MEDIUM5.9Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081...
CVE-2020-11488MEDIUM6.7NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior...
CVE-2020-11484MEDIUM4.9NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a vulnerability in the AMI BMC firmw...
CVE-2020-24712MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.
CVE-2020-24711MEDIUM6.5The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via...
CVE-2020-24710MEDIUM5.3Gophish before 0.11.0 allows SSRF attacks.
CVE-2020-24709MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template.
CVE-2020-24708MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.
CVE-2020-27980MEDIUM5.4Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to...
CVE-2020-27742MEDIUM6.5An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to...
CVE-2020-27741MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbit...
CVE-2020-27740MEDIUM5.3Citadel WebCit through 926 allows unauthenticated remote attackers to enumerate valid users within the platform. NOTE: t...
CVE-2020-25204MEDIUM5.5The God Kings application 0.60.1 for Android exposes a broadcast receiver to other apps called com.innogames.core.fronte...
CVE-2020-16261MEDIUM6.8Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.
CVE-2020-4782MEDIUM6.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the sys...
CVE-2020-27974MEDIUM6.1NeoPost Mail Accounting Software Pro 5.0.6 allows php/Commun/FUS_SCM_BlockStart.php?code= XSS.
CVE-2020-24303MEDIUM6.1Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
CVE-2020-8263MEDIUM5.4A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct...
CVE-2020-8262MEDIUM6.1A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Sit...
CVE-2020-8261MEDIUM4.3A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.
CVE-2020-8255MEDIUM4.9A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform...
CVE-2020-6829MEDIUM5.3When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial i...
CVE-2020-27957MEDIUM5.4The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certa...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now