2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-26182MEDIUM6.5Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote...
CVE-2020-9976MEDIUM5.5A logic issue was addressed with improved state management. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, ...
CVE-2020-9968MEDIUM5.5A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.0 and iPadOS 14.0, macOS Catalina ...
CVE-2020-9964MEDIUM5.5A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 14.0 and iPadOS 14...
CVE-2020-9946MEDIUM6.8This issue was addressed with improved checks. This issue is fixed in iOS 14.0 and iPadOS 14.0, watchOS 7.0. The screen ...
CVE-2020-9934MEDIUM5.5An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue...
CVE-2020-9925MEDIUM6.1A logic issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8...
CVE-2020-9916MEDIUM5.3A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13...
CVE-2020-9915MEDIUM6.5An access issue existed in Content Security Policy. This issue was addressed with improved access restrictions. This iss...
CVE-2020-9913MEDIUM5.5This issue was addressed with improved data protection. This issue is fixed in macOS Catalina 10.15.6. A local user may ...
CVE-2020-9909MEDIUM5.9An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS...
CVE-2020-9894MEDIUM4.3An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvO...
CVE-2020-9885MEDIUM5.5An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verification. This issue i...
CVE-2020-15157MEDIUM6.1In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability...
CVE-2020-26672MEDIUM5.4Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user in...
CVE-2020-24408MEDIUM6.1Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upl...
CVE-2020-16270MEDIUM6.1OLIMPOKS under 3.3.39 allows Auth/Admin ErrorMessage XSS. Remote Attacker can use discovered vulnerability to inject mal...
CVE-2020-14299MEDIUM6.5A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegat...
CVE-2020-26584MEDIUM6.1An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. The search field "Kurs suchen" on the page Kurskatalog...
CVE-2020-26583MEDIUM6.1An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (...
CVE-2020-24352MEDIUM5.5An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementa...
CVE-2020-27163MEDIUM6.1phpRedisAdmin before 1.13.2 allows XSS via the login.php username parameter.
CVE-2020-14185MEDIUM5.3Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permission...
CVE-2020-1777MEDIUM5.3Agent names that participates in a chat conversation are revealed in certain parts of the external interface as well as ...
CVE-2020-15794MEDIUM4.3A vulnerability has been identified in Desigo Insight (All versions). Some error messages in the web application show th...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now