2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-13179MEDIUM5.5Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 ar...
CVE-2020-15071MEDIUM6.1content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.
CVE-2020-13178MEDIUM6.7A function in the Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to version 20.04.1 does...
CVE-2020-13176MEDIUM6.1The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to ...
CVE-2020-13174MEDIUM6.1The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HT...
CVE-2020-15597MEDIUM5.4SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment fi...
CVE-2020-14313MEDIUM4.3An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker...
CVE-2020-10780MEDIUM6.3Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as ...
CVE-2020-10779MEDIUM6.5Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypas...
CVE-2020-10778MEDIUM6In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled a...
CVE-2020-10777MEDIUM5.4A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this...
CVE-2020-4485MEDIUM6.5IBM QRadar 7.2.0 through 7.2.9 could allow an authenticated user to disable the Wincollect service which could aid an at...
CVE-2020-16278MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Permissions component in SAINT Security Suite 8.0 through 9.8.20 could...
CVE-2020-16275MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.2...
CVE-2020-15139MEDIUM6.1In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rende...
CVE-2020-9245MEDIUM5.5HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions earlier than 10.1.0....
CVE-2020-9243MEDIUM5.5HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a denial of service vulnerability. The system doe...
CVE-2020-17480MEDIUM6.1TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by...
CVE-2020-15662MEDIUM6.5A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the ...
CVE-2020-15661MEDIUM6.5A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaki...
CVE-2020-15658MEDIUM6.5The code for downloading files did not properly take care of special characters, which led to an attacker being able to ...
CVE-2020-15655MEDIUM6.5A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leadi...
CVE-2020-15654MEDIUM6.5When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting ...
CVE-2020-15653MEDIUM6.5An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to...
CVE-2020-15652MEDIUM6.5By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now