2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-3996MEDIUM5.5Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in infor...
CVE-2020-27675MEDIUM4.7An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_ba...
CVE-2020-27674MEDIUM5.3An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying ke...
CVE-2020-27673MEDIUM5.5An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a d...
CVE-2020-15682MEDIUM6.5When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application...
CVE-2020-15680MEDIUM5.3If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguis...
CVE-2020-9997MEDIUM5.5An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.1...
CVE-2020-9939MEDIUM6.4This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.6. A local user may be able t...
CVE-2020-9935MEDIUM4.3A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.6. A user may be...
CVE-2020-9902MEDIUM5.5An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macO...
CVE-2020-27666MEDIUM5.4Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.
CVE-2020-9810MEDIUM6.8A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. A person with phy...
CVE-2020-9787MEDIUM5.3A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina ...
CVE-2020-9772MEDIUM5.5A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina ...
CVE-2020-3918MEDIUM5.5An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, mac...
CVE-2020-27533MEDIUM5.4A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to ...
CVE-2020-26650MEDIUM5.3AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
CVE-2020-27646MEDIUM6.5Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.
CVE-2020-27642MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Gre...
CVE-2020-27621MEDIUM4.3The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific u...
CVE-2020-27620MEDIUM6.1The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. ...
CVE-2020-24421MEDIUM5.5Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occurs when handling a ma...
CVE-2020-17454MEDIUM6.1WSO2 API Manager 3.1.0 and earlier has reflected XSS on the "publisher" component's admin interface. More precisely, it ...
CVE-2020-27344MEDIUM6.1The cm-download-manager plugin before 2.8.0 for WordPress allows XSS.
CVE-2020-3599MEDIUM6.1A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now