2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-3197MEDIUM5.3A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and...
CVE-2020-3150MEDIUM5.9A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could all...
CVE-2020-4316MEDIUM4.7IBM Publishing Engine 6.0.6, 6.0.6.1, and 7.0 does not set the secure attribute on authorization tokens or session cooki...
CVE-2020-15780MEDIUM6.7An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI ta...
CVE-2020-15107MEDIUM5.3In openenclave before 0.10.0, enclaves that use x87 FPU operations are vulnerable to tampering by a malicious host appli...
CVE-2020-9311MEDIUM5.4In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile ...
CVE-2020-6165MEDIUM5.3SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This aff...
CVE-2020-15051MEDIUM6.1An issue was discovered in Artica Proxy before 4.30.000000. Stored XSS exists via the Server Domain Name, Your Email Add...
CVE-2020-14982MEDIUM6.5A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352prem...
CVE-2020-13788MEDIUM4.3Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of ...
CVE-2020-15718MEDIUM6.1RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php sc...
CVE-2020-15366MEDIUM5.6An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON sc...
CVE-2020-14065MEDIUM6.5IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space.
CVE-2020-14064MEDIUM6.5IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.
CVE-2020-11437MEDIUM4.3LibreHealth EMR v2.0.0 is affected by SQL injection allowing low-privilege authenticated users to enumerate the database...
CVE-2020-15717MEDIUM6.1RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script...
CVE-2020-15716MEDIUM6.1RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php scrip...
CVE-2020-2978MEDIUM4.1Vulnerability in the Oracle Database - Enterprise Edition component of Oracle Database Server. Supported versions that a...
CVE-2020-2977MEDIUM4.6Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte...
CVE-2020-2976MEDIUM5.4Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte...
CVE-2020-2975MEDIUM5.4Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte...
CVE-2020-2974MEDIUM5.4Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte...
CVE-2020-2973MEDIUM5.4Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte...
CVE-2020-2972MEDIUM5.4Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte...
CVE-2020-2971MEDIUM5.4Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now