2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-5620MEDIUM5.4Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary s...
CVE-2020-5619MEDIUM5.4Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary s...
CVE-2020-5541MEDIUM6.1Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary site...
CVE-2020-5540MEDIUM6.1Cross-site scripting vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to inject arbitrary script o...
CVE-2020-24613MEDIUM6.8wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in t...
CVE-2020-24612MEDIUM4.7An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config...
CVE-2020-10775MEDIUM5.3An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to r...
CVE-2020-4598MEDIUM6.1IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect a...
CVE-2020-4593MEDIUM4.4IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. I...
CVE-2020-4383MEDIUM6.5IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denia...
CVE-2020-4382MEDIUM5.5IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denia...
CVE-2020-4170MEDIUM4.3IBM Security Guardium Insights 2.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execut...
CVE-2020-4165MEDIUM5.4IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persu...
CVE-2020-19890MEDIUM4.9DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as the...
CVE-2020-19888MEDIUM5.9DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.p...
CVE-2020-19887MEDIUM4.8DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_desc...
CVE-2020-19885MEDIUM4.8DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name...
CVE-2020-19884MEDIUM4.8DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php ...
CVE-2020-19883MEDIUM4.8DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for...
CVE-2020-19882MEDIUM4.8DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in...
CVE-2020-19881MEDIUM4.8DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 f...
CVE-2020-19880MEDIUM6.1DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A...
CVE-2020-19879MEDIUM6.1DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcms\pa...
CVE-2020-14367MEDIUM6A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file i...
CVE-2020-19877MEDIUM5.3DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now