2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-26917MEDIUM4.8Certain NETGEAR devices are affected by stored XSS. This affects EX7000 before 1.0.1.78, R6250 before 1.0.4.34, R6400 be...
CVE-2020-26916MEDIUM6.3Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6200 before 1.1.00.3...
CVE-2020-26915MEDIUM4.8Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b...
CVE-2020-26913MEDIUM6.8Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor...
CVE-2020-26910MEDIUM6.8Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.10, ...
CVE-2020-26901MEDIUM6.5Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK752 before 3.2.15.25, RBR75...
CVE-2020-26899MEDIUM6.5Certain NETGEAR devices are affected by disclosure of sensitive information. This affects CBR40 before 2.5.0.10, RBK752 ...
CVE-2020-26162MEDIUM6.1Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description p...
CVE-2020-13626MEDIUM4.6OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authori...
CVE-2020-15241MEDIUM6.1TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vul...
CVE-2020-15242MEDIUM6.1Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the t...
CVE-2020-5389MEDIUM6.5Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain...
CVE-2020-24301MEDIUM6.1Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability ...
CVE-2020-15646MEDIUM5.9If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange ...
CVE-2020-13344MEDIUM4.4An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are sto...
CVE-2020-13339MEDIUM6.5An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview...
CVE-2020-12401MEDIUM4.7During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication w...
CVE-2020-12400MEDIUM4.7When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulti...
CVE-2020-2298MEDIUM6.5Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attac...
CVE-2020-2296MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to ...
CVE-2020-2295MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attac...
CVE-2020-2294MEDIUM6.5Jenkins Maven Cascade Release Plugin 1.3.2 and earlier does not perform permission checks in several HTTP endpoints, all...
CVE-2020-2293MEDIUM6.5Jenkins Persona Plugin 2.4 and earlier allows users with Overall/Read permission to read arbitrary files on the Jenkins ...
CVE-2020-2292MEDIUM5.4Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cr...
CVE-2020-2290MEDIUM5.4Jenkins Active Choices Plugin 2.4 and earlier does not escape some return values of sandboxed scripts for Reactive Refer...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now