2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-15263MEDIUM6.1In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not e...
CVE-2020-15245MEDIUM4.3In Sylius before versions 1.6.9, 1.7.9 and 1.8.3, the user may register in a shop by email mail@example.com, verify it, ...
CVE-2020-13937MEDIUM5.3Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2....
CVE-2020-10746MEDIUM6.1A flaw was found in Infinispan (org.infinispan:infinispan-server-runtime) version 10, where it permits local access to c...
CVE-2020-9111MEDIUM4.5E6878-370 versions 10.0.3.1(H557SP27C233),10.0.3.1(H563SP21C233) and E6878-870 versions 10.0.3.1(H557SP27C233),10.0.3.1(...
CVE-2020-9092MEDIUM4.6HUAWEI Mate 20 versions earlier than 10.1.0.163(C00E160R3P8) have a JavaScript injection vulnerability. A module does no...
CVE-2020-24375MEDIUM6.5A DNS rebinding vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
CVE-2020-11496MEDIUM6.7Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitra...
CVE-2020-26891MEDIUM6.1AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET para...
CVE-2020-8929MEDIUM5.3A mis-handling of invalid unicode characters in the Java implementation of Tink versions prior to 1.5 allows an attacker...
CVE-2020-15910MEDIUM4.7SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible...
CVE-2020-13893MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Sage EasyPay 10.7.5.10 allow authenticated attackers to in...
CVE-2020-16978MEDIUM5.4<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a sp...
CVE-2020-16956MEDIUM5.4<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a sp...
CVE-2020-16953MEDIUM6.5<p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in m...
CVE-2020-16950MEDIUM5<p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in m...
CVE-2020-16949MEDIUM4.7<p>A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle obj...
CVE-2020-16948MEDIUM6.5<p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in m...
CVE-2020-16943MEDIUM6.5<p>An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who su...
CVE-2020-16942MEDIUM4.1<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder struc...
CVE-2020-16941MEDIUM4.1<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder struc...
CVE-2020-16938MEDIUM5.5<p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attac...
CVE-2020-16937MEDIUM4.7<p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attac...
CVE-2020-16922MEDIUM5.3<p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully expl...
CVE-2020-16921MEDIUM5.5<p>An information disclosure vulnerability exists in Text Services Framework when it fails to properly handle objects in...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now