2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-25092MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/cl...
CVE-2020-25091MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php.
CVE-2020-25090MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php.
CVE-2020-25089MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php.
CVE-2020-25088MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.
CVE-2020-25087MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/langua...
CVE-2020-25086MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminU...
CVE-2020-5418MEDIUM4.3Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controll...
CVE-2020-5379MEDIUM6.8Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacke...
CVE-2020-5378MEDIUM6.8Dell G7 17 7790 BIOS versions prior to 1.13.2 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacke...
CVE-2020-5376MEDIUM6.8Dell Inspiron 7347 BIOS versions prior to A13 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacke...
CVE-2020-8576MEDIUM5.4Clustered Data ONTAP versions prior to 9.3P19, 9.5P14, 9.6P9 and 9.7 are susceptible to a vulnerability which when succe...
CVE-2020-4546MEDIUM5.4IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2020-4522MEDIUM5.4IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2020-4445MEDIUM5.4IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2020-25026MEDIUM4.3The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows In...
CVE-2020-25025MEDIUM4.3The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows I...
CVE-2020-24553MEDIUM6.1Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a ...
CVE-2020-15811MEDIUM6.5An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitt...
CVE-2020-15810MEDIUM6.5An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggl...
CVE-2020-12621MEDIUM6.1The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-c...
CVE-2020-16150MEDIUM5.5A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23...
CVE-2020-24604MEDIUM6.1A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows rem...
CVE-2020-24602MEDIUM6.1Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute ar...
CVE-2020-24601MEDIUM6.1In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now