2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-17551MEDIUM4.8ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution.
CVE-2020-26870MEDIUM6.1Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily...
CVE-2020-24722MEDIUM5.9An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in CO...
CVE-2020-14355MEDIUM6.6Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display syste...
CVE-2020-25343MEDIUM5.4Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script o...
CVE-2020-13346MEDIUM6.5Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allow...
CVE-2020-13335MEDIUM4.3Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account w...
CVE-2020-14183MEDIUM4.3Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jir...
CVE-2020-26603MEDIUM5.3An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Sticker Center allows direc...
CVE-2020-26599MEDIUM5.3An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can ...
CVE-2020-13345MEDIUM5.4An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes
CVE-2020-13333MEDIUM4.3A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a lin...
CVE-2020-1904MEDIUM5.5A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have...
CVE-2020-1903MEDIUM5.5An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for i...
CVE-2020-1901MEDIUM5.3Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application...
CVE-2020-15215MEDIUM5.6Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using b...
CVE-2020-4528MEDIUM5.5IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under spe...
CVE-2020-25641MEDIUM5.5A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec reques...
CVE-2020-25637MEDIUM6.7A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting i...
CVE-2020-25986MEDIUM6.5A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user.
CVE-2020-23832MEDIUM6.1A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System...
CVE-2020-5631MEDIUM6.1Stored cross-site scripting vulnerability in CMONOS.JP ver2.0.20191009 and earlier allows remote attackers to inject arb...
CVE-2020-26572MEDIUM5.5The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.
CVE-2020-26571MEDIUM5.5The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu...
CVE-2020-26570MEDIUM5.5The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now