2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-13819MEDIUM6.1Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
CVE-2020-15109MEDIUM5.3In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering addre...
CVE-2020-16847MEDIUM6.1Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in ...
CVE-2020-16843MEDIUM5.9In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. ...
CVE-2020-15944MEDIUM5.4An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is ...
CVE-2020-4631MEDIUM5.5IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned acce...
CVE-2020-4542MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2020-4525MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2020-4410MEDIUM4.3IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to send a specially crafted HTTP GET ...
CVE-2020-4396MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2020-11584MEDIUM6.1A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary Ja...
CVE-2020-11583MEDIUM6.1A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrar...
CVE-2020-8575MEDIUM4.4Active IQ Unified Manager for VMware vSphere and Windows versions prior to 9.5 are susceptible to a vulnerability which ...
CVE-2020-16131MEDIUM6.1Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.
CVE-2020-14319MEDIUM5.9It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in ca...
CVE-2020-13820MEDIUM6.1Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
CVE-2020-12739MEDIUM5.3A denial-of-service vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remot...
CVE-2020-16269MEDIUM5.5radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwa...
CVE-2020-4560MEDIUM6.1IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed ...
CVE-2020-4328MEDIUM6.3IBM Financial Transaction Manager 3.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted S...
CVE-2020-14311MEDIUM6There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a sy...
CVE-2020-14310MEDIUM6There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max...
CVE-2020-5414MEDIUM5.7VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x vers...
CVE-2020-15870MEDIUM6.1Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
CVE-2020-15869MEDIUM5.4Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now