2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-13923MEDIUM5.3IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04
CVE-2020-7292MEDIUM4.3Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attac...
CVE-2020-5765MEDIUM5.4Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during sc...
CVE-2020-4100MEDIUM4.4"HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which comp...
CVE-2020-1468MEDIUM6.5An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m...
CVE-2020-1462MEDIUM4.3An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), ...
CVE-2020-1456MEDIUM5.4A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2020-1454MEDIUM5.4This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affecte...
CVE-2020-1451MEDIUM5.4A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2020-1450MEDIUM5.4A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2020-1445MEDIUM5.5An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, ak...
CVE-2020-1444MEDIUM4.3A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email mes...
CVE-2020-1443MEDIUM5.4A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requ...
CVE-2020-1442MEDIUM6.1A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, a...
CVE-2020-1434MEDIUM5.3An elevation of privilege vulnerability exists in the way that the Windows Sync Host Service handles objects in memory, ...
CVE-2020-1433MEDIUM6.5An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka ...
CVE-2020-1432MEDIUM4.3An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for...
CVE-2020-1426MEDIUM5.5An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window...
CVE-2020-1420MEDIUM5.5An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploi...
CVE-2020-1419MEDIUM5.5An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, ak...
CVE-2020-1398MEDIUM6.8An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An...
CVE-2020-1397MEDIUM6.5An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle ob...
CVE-2020-1391MEDIUM5.5An information disclosure vulnerability exists when the Windows Agent Activation Runtime (AarSvc) fails to properly hand...
CVE-2020-1389MEDIUM5.5An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, ak...
CVE-2020-1386MEDIUM5.5An information vulnerability exists when Windows Connected User Experiences and Telemetry Service improperly discloses f...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now