2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-24008MEDIUM5.3Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in me...
CVE-2020-19007MEDIUM5.4Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code suppl...
CVE-2020-24314MEDIUM6.1Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoin...
CVE-2020-24313MEDIUM6.1Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the valu...
CVE-2020-15499MEDIUM6.1An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. They allow XSS via spoofed Release Notes on...
CVE-2020-15498MEDIUM5.9An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. The router accepts an arbitrary server cert...
CVE-2020-16193MEDIUM5.4osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.
CVE-2020-7309MEDIUM4.8Cross Site Scripting vulnerability in ePO extension in McAfee Application Control (MAC) prior to 8.3.1 allows administra...
CVE-2020-24656MEDIUM6.5Maltego before 4.2.12 allows XXE attacks.
CVE-2020-19005MEDIUM5.7zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can ...
CVE-2020-17402MEDIUM6.5This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt...
CVE-2020-17401MEDIUM6This vulnerability allows local attackers to disclose sensitive informations on affected installations of Parallels Desk...
CVE-2020-17398MEDIUM6.5This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.4....
CVE-2020-17394MEDIUM6This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt...
CVE-2020-17393MEDIUM6.5This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-...
CVE-2020-17391MEDIUM6.5This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-...
CVE-2020-7824MEDIUM6.5A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get admi...
CVE-2020-24622MEDIUM4.9In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
CVE-2020-16197MEDIUM4.3An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that...
CVE-2020-24609MEDIUM6.1TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the X...
CVE-2020-14042MEDIUM6.1** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and late...
CVE-2020-24242MEDIUM5.5In Netwide Assembler (NASM) 2.15rc10, SEGV can be triggered in tok_text in asm/preproc.c by accessing READ memory.
CVE-2020-24241MEDIUM5.5In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c.
CVE-2020-24240MEDIUM5.5GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is...
CVE-2020-17386MEDIUM6.5Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user,...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now