2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-15020MEDIUM5.4An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stor...
CVE-2020-25033MEDIUM6.1The Blubrry subscribe-sidebar (aka Subscribe Sidebar) plugin 1.3.1 for WordPress allows subscribe_sidebar.php&status= re...
CVE-2020-24104MEDIUM6.1XSS on the PIX-Link Repeater/Router LV-WR07 with firmware v28K.Router.20170904 allows attackers to steal credentials wit...
CVE-2020-24223MEDIUM6.1Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
CVE-2020-24917MEDIUM6.1osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php...
CVE-2020-8244MEDIUM6.5A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply...
CVE-2020-24928MEDIUM5.3managers/socketManager.ts in PreMiD through 2.1.3 has a locally hosted socketio web server (port 3020) open to all origi...
CVE-2020-24898MEDIUM6.5The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Tabl...
CVE-2020-16610MEDIUM4.3Hoosk Codeigniter CMS before 1.7.2 is affected by a Cross Site Request Forgery (CSRF). When an attacker induces authenti...
CVE-2020-5625MEDIUM6.1Cross-site scripting vulnerability in XooNIps 3.48 and earlier allows remote attackers to inject an arbitrary script via...
CVE-2020-5623MEDIUM6.1NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attacke...
CVE-2020-5621MEDIUM4.3Cross-site request forgery (CSRF) vulnerability in NETGEAR switching hubs (GS716Tv2 Firmware version 5.4.2.30 and earlie...
CVE-2020-10517MEDIUM4.3An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of ...
CVE-2020-24618MEDIUM6.5In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65...
CVE-2020-5383MEDIUM5.3Dell EMC Isilon OneFS version 8.2.2 and Dell EMC PowerScale OneFS version 9.0.0 contains a buffer overflow vulnerability...
CVE-2020-24706MEDIUM6.1An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager through...
CVE-2020-24704MEDIUM6.1An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager 2.2.0, ...
CVE-2020-24390MEDIUM6.1eonweb in EyesOfNetwork before 5.3-7 does not properly escape the username on the /module/admin_logs page, which might a...
CVE-2020-23576MEDIUM5.4Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab.
CVE-2020-23984MEDIUM5.4Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-ta...
CVE-2020-23983MEDIUM5.4Michael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags.
CVE-2020-23982MEDIUM6.1DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php'
CVE-2020-23981MEDIUM6.113enforme CMS 1.0 has Cross Site Scripting via the "content.php" id parameter.
CVE-2020-23977MEDIUM6.1KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter.
CVE-2020-23975MEDIUM6.1Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has cross site scripting via the 'search.php' id parameter.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now