2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-14194MEDIUM5.4Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.
CVE-2020-12759MEDIUM6.1Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook.
CVE-2020-12619MEDIUM5.9MailMate before 1.11 automatically imported S/MIME certificates and thereby silently replaced existing ones. This allowe...
CVE-2020-12618MEDIUM4.8eM Client before 7.2.33412.0 automatically imported S/MIME certificates and thereby silently replaced existing ones. Thi...
CVE-2020-4687MEDIUM4.3IBM Content Navigator 3.0.7 and 3.0.8 could allow an authenticated user to view cached content of another user that they...
CVE-2020-16280MEDIUM5.5Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several ex...
CVE-2020-15634MEDIUM6.3This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670...
CVE-2020-15532MEDIUM6.5Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air denia...
CVE-2020-15119MEDIUM5.4In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerously...
CVE-2020-13825MEDIUM6.1A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HT...
CVE-2020-23574MEDIUM6.5When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uplo...
CVE-2020-9712MEDIUM5.5Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...
CVE-2020-9703MEDIUM5.5Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...
CVE-2020-9702MEDIUM5.5Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...
CVE-2020-9697MEDIUM5.5Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...
CVE-2020-9696MEDIUM5.5Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...
CVE-2020-4653MEDIUM6.1IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By ...
CVE-2020-4648MEDIUM6.5A vulnerability exsists in IBM Planning Analytics 2.0 whereby avatars in Planning Analytics Workspace could be modified ...
CVE-2020-4381MEDIUM6.5IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.6 could allow an authenticated user to cause a denia...
CVE-2020-15926MEDIUM6.1Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct ...
CVE-2020-9415MEDIUM6.5The TIBCO Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtual...
CVE-2020-7019MEDIUM6.5In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Le...
CVE-2020-14333MEDIUM6.1A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable par...
CVE-2020-13183MEDIUM6.1Reflected Cross Site Scripting in Teradici PCoIP Management Console prior to 20.07 could allow an attacker to take over ...
CVE-2020-12480MEDIUM6.5In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now