2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-14307MEDIUM6.5A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where Sess...
CVE-2020-14297MEDIUM6.5A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction o...
CVE-2020-14175MEDIUM5.4Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or Java...
CVE-2020-15919MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.
CVE-2020-15918MEDIUM5.4Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.
CVE-2020-7520MEDIUM4.7A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Updat...
CVE-2020-7517MEDIUM5.5A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy Builder (Version 1.4.7.2 and older...
CVE-2020-11625MEDIUM5.3An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Ind...
CVE-2020-11623MEDIUM6.8An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Ind...
CVE-2020-8557MEDIUM5.5The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage ...
CVE-2020-4447MEDIUM5.4IBM FileNet Content Manager 5.5.3 and 5.5.4 is vulnerable to cross-site scripting. This vulnerability allows users to em...
CVE-2020-12638MEDIUM6.8An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3....
CVE-2020-10919MEDIUM5.9This vulnerability allows remote attackers to disclose sensitive information on affected installations of C-MORE HMI EA9...
CVE-2020-15912MEDIUM6.5Tesla Model 3 vehicles allow attackers to open a door by leveraging access to a legitimate key card, and then using NFC ...
CVE-2020-15885MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to i...
CVE-2020-15883MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability in the managedinstalls module before 2.6 for MunkiReport allows remote attack...
CVE-2020-15881MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability in the munki_facts (aka Munki Conditions) module before 1.5 for MunkiReport a...
CVE-2020-15126MEDIUM6.5In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass a...
CVE-2020-15902MEDIUM6.1Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
CVE-2020-4399MEDIUM6.5IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could allow an authenticated user to send malformed requests to cause a denial ...
CVE-2020-4397MEDIUM5.9IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an att...
CVE-2020-4369MEDIUM5.5IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores highly sensitive information in cleartext that could be obtained by a us...
CVE-2020-9686MEDIUM6.5Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful expl...
CVE-2020-9679MEDIUM6.5Adobe Prelude versions 9.0 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to a...
CVE-2020-9665MEDIUM6.1Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a stored cross-site scripting vulnerability. Success...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now