2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-26134MEDIUM6.1Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode.
CVE-2020-17482MEDIUM4.3An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to inser...
CVE-2020-14294MEDIUM6.1An issue was discovered in Secudos Qiata FTA 1.70.19. The comment feature allows persistent XSS that is executed when re...
CVE-2020-13168MEDIUM6.1SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.
CVE-2020-26536MEDIUM5.5An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PD...
CVE-2020-26524MEDIUM5.3CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.
CVE-2020-26523MEDIUM6.1Froala Editor before 3.2.2 allows XSS via pasted content.
CVE-2020-26519MEDIUM5.5Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a de...
CVE-2020-5789MEDIUM6.5Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the cont...
CVE-2020-5788MEDIUM6.5Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitr...
CVE-2020-5787MEDIUM6.5Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitr...
CVE-2020-5785MEDIUM6.1Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct r...
CVE-2020-5784MEDIUM6.5Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the applicatio...
CVE-2020-5387MEDIUM4.4Dell XPS 13 9370 BIOS versions prior to 1.13.1 contains an Improper Exception Handling vulnerability. A local attacker w...
CVE-2020-14223MEDIUM6.1HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed i...
CVE-2020-13940MEDIUM5.5In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider o...
CVE-2020-15677MEDIUM6.1By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the down...
CVE-2020-15676MEDIUM6.1Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScr...
CVE-2020-15668MEDIUM4.3A lock was missing when accessing a data structure and importing certificate information into the trust database. This v...
CVE-2020-15666MEDIUM6.5When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was...
CVE-2020-15665MEDIUM4.3Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. T...
CVE-2020-15664MEDIUM6.5By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access t...
CVE-2020-25200MEDIUM5.3Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Ini...
CVE-2020-15228MEDIUM5In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Act...
CVE-2020-16844MEDIUM6.8In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now