2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-23647MEDIUM6.1Cross Site Scripting (XSS) vulnerability in BoxBilling 4.19, 4.19.1, 4.20, and 4.21 allows remote attackers to run arbit...
CVE-2020-21643MEDIUM6.1Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback paramete...
CVE-2020-4729MEDIUM5.3IBM Counter Fraud Management for Safer Payments 5.7.0.00 through 5.7.0.10, 6.0.0.00 through 6.0.0.07, 6.1.0.00 through 6...
CVE-2020-28163MEDIUM6.5libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-t...
CVE-2020-27545MEDIUM6.5libdwarf before 20201017 has a one-byte out-of-bounds read because of an invalid pointer dereference via an invalid line...
CVE-2020-24736MEDIUM5.5Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service ...
CVE-2020-11935MEDIUM5.5It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacke...
CVE-2020-23327MEDIUM6.1Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows a local attacker to execute arbitrary code via...
CVE-2020-22533MEDIUM6.1Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang param...
CVE-2020-20522MEDIUM6.1Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the reg...
CVE-2020-20521MEDIUM6.1Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the com...
CVE-2020-19850MEDIUM6.5An issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP ...
CVE-2020-19699MEDIUM6.1Cross Site Scripting vulnerability found in KOHGYLW Kiftd v.1.0.18 allows a remote attacker to execute arbitrary code vi...
CVE-2020-19698MEDIUM6.1Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code ...
CVE-2020-19697MEDIUM6.1Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code ...
CVE-2020-19277MEDIUM5.4Cross Site Scripting vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code v...
CVE-2020-36692MEDIUM5.4A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows e...
CVE-2020-36691MEDIUM5.5An issue was discovered in the Linux kernel before 5.8. lib/nlattr.c allows attackers to cause a denial of service (unbo...
CVE-2020-24857MEDIUM6.1Cross Site Scripting vulnerabilty found in IXPManager v.5.6.0 allows attackers to excute arbitrary code via the looking ...
CVE-2020-36670MEDIUM6.3The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to,...
CVE-2020-36668MEDIUM4.3The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to sensitive information disclosure in v...
CVE-2020-36667MEDIUM5.4The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location changes...
CVE-2020-36665MEDIUM6.1A vulnerability was found in Artesãos SEOTools up to 0.17.1 and classified as critical. This issue affects the function ...
CVE-2020-36664MEDIUM6.1A vulnerability has been found in Artesãos SEOTools up to 0.17.1 and classified as problematic. This vulnerability affec...
CVE-2020-36663MEDIUM6.1A vulnerability, which was classified as problematic, was found in Artesãos SEOTools up to 0.17.1. This affects the func...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now