2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13819 | MEDIUM | 6.1 | 0.9% | Aug 5, 2020 | Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request. |
| CVE-2020-15109 | MEDIUM | 5.3 | 0.9% | Aug 4, 2020 | In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering addre... |
| CVE-2020-16847 | MEDIUM | 6.1 | 0.6% | Aug 4, 2020 | Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in ... |
| CVE-2020-16843 | MEDIUM | 5.9 | 1.7% | Aug 4, 2020 | In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. ... |
| CVE-2020-15944 | MEDIUM | 5.4 | 1.3% | Aug 4, 2020 | An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is ... |
| CVE-2020-4631 | MEDIUM | 5.5 | 0.2% | Aug 4, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned acce... |
| CVE-2020-4542 | MEDIUM | 5.4 | 0.6% | Aug 4, 2020 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2020-4525 | MEDIUM | 5.4 | 0.6% | Aug 4, 2020 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2020-4410 | MEDIUM | 4.3 | 1.0% | Aug 4, 2020 | IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to send a specially crafted HTTP GET ... |
| CVE-2020-4396 | MEDIUM | 5.4 | 0.6% | Aug 4, 2020 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2020-11584 | MEDIUM | 6.1 | 0.9% | Aug 3, 2020 | A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary Ja... |
| CVE-2020-11583 | MEDIUM | 6.1 | 1.0% | Aug 3, 2020 | A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrar... |
| CVE-2020-8575 | MEDIUM | 4.4 | 0.3% | Aug 3, 2020 | Active IQ Unified Manager for VMware vSphere and Windows versions prior to 9.5 are susceptible to a vulnerability which ... |
| CVE-2020-16131 | MEDIUM | 6.1 | 0.7% | Aug 3, 2020 | Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php. |
| CVE-2020-14319 | MEDIUM | 5.9 | 0.3% | Aug 3, 2020 | It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in ca... |
| CVE-2020-13820 | MEDIUM | 6.1 | 3.5% | Aug 3, 2020 | Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request. |
| CVE-2020-12739 | MEDIUM | 5.3 | 1.9% | Aug 3, 2020 | A denial-of-service vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remot... |
| CVE-2020-16269 | MEDIUM | 5.5 | 1.0% | Aug 3, 2020 | radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwa... |
| CVE-2020-4560 | MEDIUM | 6.1 | 0.9% | Aug 3, 2020 | IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2020-4328 | MEDIUM | 6.3 | 1.2% | Aug 3, 2020 | IBM Financial Transaction Manager 3.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted S... |
| CVE-2020-14311 | MEDIUM | 6 | 0.5% | Jul 31, 2020 | There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a sy... |
| CVE-2020-14310 | MEDIUM | 6 | 0.5% | Jul 31, 2020 | There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max... |
| CVE-2020-5414 | MEDIUM | 5.7 | 0.7% | Jul 31, 2020 | VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x vers... |
| CVE-2020-15870 | MEDIUM | 6.1 | 0.7% | Jul 31, 2020 | Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2). |
| CVE-2020-15869 | MEDIUM | 5.4 | 0.7% | Jul 31, 2020 | Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2). |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now