2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25092 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/cl... |
| CVE-2020-25091 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php. |
| CVE-2020-25090 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php. |
| CVE-2020-25089 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php. |
| CVE-2020-25088 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php. |
| CVE-2020-25087 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/langua... |
| CVE-2020-25086 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminU... |
| CVE-2020-5418 | MEDIUM | 4.3 | 0.6% | Sep 3, 2020 | Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controll... |
| CVE-2020-5379 | MEDIUM | 6.8 | 0.4% | Sep 2, 2020 | Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacke... |
| CVE-2020-5378 | MEDIUM | 6.8 | 0.4% | Sep 2, 2020 | Dell G7 17 7790 BIOS versions prior to 1.13.2 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacke... |
| CVE-2020-5376 | MEDIUM | 6.8 | 0.4% | Sep 2, 2020 | Dell Inspiron 7347 BIOS versions prior to A13 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacke... |
| CVE-2020-8576 | MEDIUM | 5.4 | 0.7% | Sep 2, 2020 | Clustered Data ONTAP versions prior to 9.3P19, 9.5P14, 9.6P9 and 9.7 are susceptible to a vulnerability which when succe... |
| CVE-2020-4546 | MEDIUM | 5.4 | 0.6% | Sep 2, 2020 | IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2020-4522 | MEDIUM | 5.4 | 0.6% | Sep 2, 2020 | IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2020-4445 | MEDIUM | 5.4 | 0.6% | Sep 2, 2020 | IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2020-25026 | MEDIUM | 4.3 | 0.8% | Sep 2, 2020 | The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows In... |
| CVE-2020-25025 | MEDIUM | 4.3 | 0.8% | Sep 2, 2020 | The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows I... |
| CVE-2020-24553 | MEDIUM | 6.1 | 3.6% | Sep 2, 2020 | Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a ... |
| CVE-2020-15811 | MEDIUM | 6.5 | 4.2% | Sep 2, 2020 | An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitt... |
| CVE-2020-15810 | MEDIUM | 6.5 | 2.5% | Sep 2, 2020 | An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggl... |
| CVE-2020-12621 | MEDIUM | 6.1 | 0.3% | Sep 2, 2020 | The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-c... |
| CVE-2020-16150 | MEDIUM | 5.5 | 0.4% | Sep 2, 2020 | A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23... |
| CVE-2020-24604 | MEDIUM | 6.1 | 1.2% | Sep 2, 2020 | A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows rem... |
| CVE-2020-24602 | MEDIUM | 6.1 | 1.0% | Sep 2, 2020 | Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute ar... |
| CVE-2020-24601 | MEDIUM | 6.1 | 0.6% | Sep 2, 2020 | In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now