2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-6872MEDIUM6.1The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes thr...
CVE-2020-15118MEDIUM5.4In Wagtail before versions 2.7.4 and 2.9.3, when a form page type is made available to Wagtail editors through the `wagt...
CVE-2020-15111MEDIUM5.4In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is...
CVE-2020-15053MEDIUM6.1An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time ...
CVE-2020-7680MEDIUM6.1docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters a...
CVE-2020-12027MEDIUM4.3All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote,...
CVE-2020-14491MEDIUM6.5OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may al...
CVE-2020-4527MEDIUM5.9IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set t...
CVE-2020-4466MEDIUM6.5IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow a remote authenticated attacker could cause a denial of service due t...
CVE-2020-4361MEDIUM4.3IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by disclosing private IP addres...
CVE-2020-9256MEDIUM6.5Huawei Mate 30 Pro smartphones with versions earlier than 10.1.0.150(C00E136R5P3) have an improper authorization vulnera...
CVE-2020-9101MEDIUM6.5There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets wit...
CVE-2020-9259MEDIUM6.5Huawei Honor V30 smartphones with versions earlier than 10.1.0.212(C00E210R5P1) have an improper authentication vulnerab...
CVE-2020-9255MEDIUM5.5Huawei Honor 10 smartphones with versions earlier than 10.0.0.178(C00E178R1P4) have a denial of service vulnerability. C...
CVE-2020-9227MEDIUM5.5Huawei Smart Phones Moana-AL00B with versions earlier than 10.1.0.166 have a missing initialization of resource vulnerab...
CVE-2020-5769MEDIUM5.4Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.02 allows a remote, authenticated attacker to conduc...
CVE-2020-5768MEDIUM4.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & News...
CVE-2020-5767MEDIUM6.5Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attack...
CVE-2020-4104MEDIUM5.4HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can us...
CVE-2020-0122MEDIUM6.7In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, th...
CVE-2020-0107MEDIUM5.5In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validati...
CVE-2020-0305MEDIUM6.4In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalati...
CVE-2020-1655MEDIUM5.3When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configur...
CVE-2020-1651MEDIUM6.5On Juniper Networks MX series, receipt of a stream of specific Layer 2 frames may cause a memory leak resulting in the p...
CVE-2020-1643MEDIUM5.5Execution of the "show ospf interface extensive" or "show ospf interface detail" CLI commands on a Juniper Networks devi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now