2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-6558MEDIUM6.5Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to byp...
CVE-2020-6547MEDIUM6.5Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain s...
CVE-2020-6538MEDIUM6.5Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to ...
CVE-2020-15966MEDIUM4.3Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced ...
CVE-2020-15959MEDIUM4.3Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced ...
CVE-2020-4731MEDIUM6.1IBM Aspera Web Application 1.9.14 PL1 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar...
CVE-2020-4590MEDIUM6.5IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server f...
CVE-2020-4315MEDIUM4.3IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or sessi...
CVE-2020-16171MEDIUM6.5An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/...
CVE-2020-14180MEDIUM4.3Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-ad...
CVE-2020-14179MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field ...
CVE-2020-14177MEDIUM6.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availabili...
CVE-2020-25789MEDIUM6.1An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript in...
CVE-2020-25786MEDIUM6.1webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header....
CVE-2020-5421MEDIUM6.5In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versio...
CVE-2020-8245MEDIUM6.1Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1...
CVE-2020-8200MEDIUM6.5Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Mi...
CVE-2020-9084MEDIUM6.5Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a use-after-free (UAF) vulnerability. An authenticated, ...
CVE-2020-25633MEDIUM5.3A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain t...
CVE-2020-7945MEDIUM5.5Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentia...
CVE-2020-16200MEDIUM6.5Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not properly control the allocation and maint...
CVE-2020-16198MEDIUM6.3When an attacker claims to have a given identity, Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, ...
CVE-2020-14506MEDIUM4.3Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not ...
CVE-2020-14390MEDIUM5.6A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-of-bounds memory writ...
CVE-2020-14021MEDIUM4.9An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The ASP.net SMS module can be used to read and validate ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now