2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-24861MEDIUM5.4GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is execu...
CVE-2020-24860MEDIUM5.4CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persisten...
CVE-2020-25830MEDIUM4.8An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inje...
CVE-2020-25781MEDIUM4.3An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes...
CVE-2020-25288MEDIUM4.8An issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafte...
CVE-2020-13336MEDIUM4.8An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored X...
CVE-2020-12869MEDIUM5.4RainbowFish PacsOne Server 6.8.4 allows XSS.
CVE-2020-25816MEDIUM6.8HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their T...
CVE-2020-25626MEDIUM6.1A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer...
CVE-2020-8256MEDIUM4.9A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain ...
CVE-2020-8238MEDIUM6.1A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could ...
CVE-2020-26137MEDIUM6.5urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserti...
CVE-2020-26043MEDIUM6.1An issue was discovered in Hoosk CMS v1.8.0. There is a XSS vulnerability in install/index.php
CVE-2020-25761MEDIUM6.1Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on ...
CVE-2020-24721MEDIUM5.7An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in CO...
CVE-2020-24570MEDIUM6.5An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resu...
CVE-2020-24569MEDIUM4.3An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection i...
CVE-2020-22842MEDIUM5.4CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/mod...
CVE-2020-22481MEDIUM6.1An issue was discovered in HFish 0.5.1. When a payload is inserted where the password is entered, XSS code is triggered ...
CVE-2020-21244MEDIUM4.9An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via...
CVE-2020-19676MEDIUM5.3Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details in...
CVE-2020-19670MEDIUM4.9In Niushop B2B2C Multi-Business Basic Edition V1.11, authentication can be bypassed, causing administrators to reset any...
CVE-2020-15595MEDIUM4.3An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to ...
CVE-2020-15594MEDIUM4.3An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration fe...
CVE-2020-13953MEDIUM5.3In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now