2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-16140MEDIUM6.1The search functionality of the Greenmart theme 2.4.2 for WordPress is vulnerable to XSS.
CVE-2020-9982MEDIUM5.5This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Apple Music 3.4.0 ...
CVE-2020-9979MEDIUM5.5A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0. An att...
CVE-2020-9860MEDIUM5.4A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 13.0.5. P...
CVE-2020-9857MEDIUM4.3An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in...
CVE-2020-3852MEDIUM5.3A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL scheme may be incorrec...
CVE-2020-6022MEDIUM5.5Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files...
CVE-2020-27182MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to in...
CVE-2020-27181MEDIUM6.5A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to c...
CVE-2020-25034MEDIUM6.5eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via th...
CVE-2020-15274MEDIUM5.4In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. W...
CVE-2020-26161MEDIUM6.1In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header...
CVE-2020-7196MEDIUM6.5The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of han...
CVE-2020-7126MEDIUM5.8A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to ...
CVE-2020-6876MEDIUM5.4A ZTE product is impacted by an XSS vulnerability. The vulnerability is caused by the lack of correct verification of cl...
CVE-2020-25470MEDIUM6.1AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added sit...
CVE-2020-27388MEDIUM5.4Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An au...
CVE-2020-24847MEDIUM4.3A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protect...
CVE-2020-3998MEDIUM6.5VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious att...
CVE-2020-3997MEDIUM5.4VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful ex...
CVE-2020-9361MEDIUM5.5CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause...
CVE-2020-15004MEDIUM4.8OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS.
CVE-2020-15003MEDIUM4.3OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string o...
CVE-2020-15002MEDIUM5OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
CVE-2020-15270MEDIUM4.3Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid....

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now