2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-13943MEDIUM4.3If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded t...
CVE-2020-13341MEDIUM4.9An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Insufficient permissi...
CVE-2020-4781MEDIUM6.5An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9 ...
CVE-2020-4780MEDIUM5.3OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Managem...
CVE-2020-4775MEDIUM5.4A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. This vulnera...
CVE-2020-4774MEDIUM5.4An XPath vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, caused by the improper handling ...
CVE-2020-4773MEDIUM6.5A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which...
CVE-2020-4699MEDIUM5.3IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive usin...
CVE-2020-4661MEDIUM5.3IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive usin...
CVE-2020-4660MEDIUM5.3IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive usin...
CVE-2020-5143MEDIUM5.3SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username...
CVE-2020-5142MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated a...
CVE-2020-5141MEDIUM6.5A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firew...
CVE-2020-5136MEDIUM6.5A buffer overflow vulnerability in SonicOS allows an authenticated attacker to cause Denial of Service (DoS) in the SSL-...
CVE-2020-5134MEDIUM6.5A vulnerability in SonicOS allows an authenticated attacker to cause out-of-bound invalid file reference leads to a fire...
CVE-2020-14184MEDIUM5.4Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Sit...
CVE-2020-26934MEDIUM6.1phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
CVE-2020-26932MEDIUM4.3debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whe...
CVE-2020-9105MEDIUM6.7Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability. Due to t...
CVE-2020-13955MEDIUM5.9HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnera...
CVE-2020-26931MEDIUM6.5Certain NETGEAR devices are affected by disclosure of sensitive information. This affects WC7500 before 6.5.5.24, WC7600...
CVE-2020-26924MEDIUM6.5Certain NETGEAR devices are affected by disclosure of sensitive information. This affects WAC720 before 3.9.1.13 and WAC...
CVE-2020-26923MEDIUM4.8Certain NETGEAR devices are affected by stored XSS. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v...
CVE-2020-26922MEDIUM6.7Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24,...
CVE-2020-26918MEDIUM4.8Certain NETGEAR devices are affected by stored XSS. This affects EX7000 before 1.0.1.78, R6250 before 1.0.4.34, R6400 be...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now