2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5620 | MEDIUM | 5.4 | 0.6% | Aug 25, 2020 | Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary s... |
| CVE-2020-5619 | MEDIUM | 5.4 | 0.7% | Aug 25, 2020 | Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary s... |
| CVE-2020-5541 | MEDIUM | 6.1 | 1.4% | Aug 25, 2020 | Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary site... |
| CVE-2020-5540 | MEDIUM | 6.1 | 1.5% | Aug 25, 2020 | Cross-site scripting vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to inject arbitrary script o... |
| CVE-2020-24613 | MEDIUM | 6.8 | 0.9% | Aug 24, 2020 | wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in t... |
| CVE-2020-24612 | MEDIUM | 4.7 | 0.3% | Aug 24, 2020 | An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config... |
| CVE-2020-10775 | MEDIUM | 5.3 | 1.8% | Aug 24, 2020 | An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to r... |
| CVE-2020-4598 | MEDIUM | 6.1 | 0.8% | Aug 24, 2020 | IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect a... |
| CVE-2020-4593 | MEDIUM | 4.4 | 0.3% | Aug 24, 2020 | IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. I... |
| CVE-2020-4383 | MEDIUM | 6.5 | 1.1% | Aug 24, 2020 | IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denia... |
| CVE-2020-4382 | MEDIUM | 5.5 | 0.3% | Aug 24, 2020 | IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denia... |
| CVE-2020-4170 | MEDIUM | 4.3 | 0.4% | Aug 24, 2020 | IBM Security Guardium Insights 2.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execut... |
| CVE-2020-4165 | MEDIUM | 5.4 | 0.6% | Aug 24, 2020 | IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persu... |
| CVE-2020-19890 | MEDIUM | 4.9 | 0.9% | Aug 24, 2020 | DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as the... |
| CVE-2020-19888 | MEDIUM | 5.9 | 0.7% | Aug 24, 2020 | DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.p... |
| CVE-2020-19887 | MEDIUM | 4.8 | 0.9% | Aug 24, 2020 | DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_desc... |
| CVE-2020-19885 | MEDIUM | 4.8 | 0.9% | Aug 24, 2020 | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name... |
| CVE-2020-19884 | MEDIUM | 4.8 | 0.6% | Aug 24, 2020 | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php ... |
| CVE-2020-19883 | MEDIUM | 4.8 | 0.7% | Aug 24, 2020 | DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for... |
| CVE-2020-19882 | MEDIUM | 4.8 | 0.7% | Aug 24, 2020 | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in... |
| CVE-2020-19881 | MEDIUM | 4.8 | 0.9% | Aug 24, 2020 | DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 f... |
| CVE-2020-19880 | MEDIUM | 6.1 | 0.9% | Aug 24, 2020 | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A... |
| CVE-2020-19879 | MEDIUM | 6.1 | 0.7% | Aug 24, 2020 | DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcms\pa... |
| CVE-2020-14367 | MEDIUM | 6 | 0.5% | Aug 24, 2020 | A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file i... |
| CVE-2020-19877 | MEDIUM | 5.3 | 1.7% | Aug 24, 2020 | DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now