2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-20628MEDIUM6.1controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.
CVE-2020-24699MEDIUM6.1The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS.
CVE-2020-20627MEDIUM5.3The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauth...
CVE-2020-20626MEDIUM5.4lara-google-analytics.php in Lara Google Analytics plugin through 2.0.4 for WordPress allows authenticated stored XSS.
CVE-2020-17465MEDIUM6.1Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vuln...
CVE-2020-13828MEDIUM5.4Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authen...
CVE-2020-13472MEDIUM4.6The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the...
CVE-2020-13471MEDIUM6.8Apex Microelectronics APM32F103 devices allow physical attackers to execute arbitrary code via a power glitch and a spec...
CVE-2020-13470MEDIUM4.6Gigadevice GD32F103 and GD32F130 devices allow physical attackers to extract data via the probing of easily accessible b...
CVE-2020-13469MEDIUM4.6The flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via th...
CVE-2020-13468MEDIUM6.8Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection i...
CVE-2020-13467MEDIUM4.6The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attacker...
CVE-2020-13466MEDIUM6.8STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power g...
CVE-2020-13465MEDIUM6.8The security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execut...
CVE-2020-13464MEDIUM4.2The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attacker...
CVE-2020-13463MEDIUM4.6The flash memory readout protection in Apex Microelectronics APM32F103 devices allows physical attackers to extract firm...
CVE-2020-5419MEDIUM6.7RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allow...
CVE-2020-13655MEDIUM6.1An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is s...
CVE-2020-13595MEDIUM6.5The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) return...
CVE-2020-13594MEDIUM6.5The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does n...
CVE-2020-12646MEDIUM5.4OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
CVE-2020-12644MEDIUM5OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.
CVE-2020-12643MEDIUM4.3OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing ...
CVE-2020-11617MEDIUM5.9The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the S...
CVE-2020-4492MEDIUM5.5IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a deni...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now