2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-15570MEDIUM5.5The parse_report() function in whoopsie.c in Whoopsie through 0.2.69 mishandles memory allocation failures, which allows...
CVE-2020-15569MEDIUM5.5PlayerGeneric.cpp in MilkyTracker through 1.02.00 has a use-after-free in the PlayerGeneric destructor.
CVE-2020-7691MEDIUM6.1In all versions of the package jspdf, it is possible to use <<script>script> in order to go over the filtering regex.
CVE-2020-7690MEDIUM6.1All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject Jav...
CVE-2020-15562MEDIUM6.1An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS v...
CVE-2020-15538MEDIUM6.1XSS can occur in We-com Municipality portal CMS 2.1.x via the cerca/ search bar.
CVE-2020-15537MEDIUM6.1An issue was discovered in the Vanguard plugin 2.1 for WordPress. XSS can occur via the mails/new title field, a product...
CVE-2020-15536MEDIUM6.1An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can...
CVE-2020-15535MEDIUM6.1An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur ...
CVE-2020-7282MEDIUM6.3Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files t...
CVE-2020-7281MEDIUM6.3Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files...
CVE-2020-14173MEDIUM5.4The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject ...
CVE-2020-8185MEDIUM6.5A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations ...
CVE-2020-8179MEDIUM4.1Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
CVE-2020-8176MEDIUM6.1A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS pay...
CVE-2020-8166MEDIUM4.3A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a g...
CVE-2020-4061MEDIUM5.4In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froa...
CVE-2020-15091MEDIUM6.5TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong bloc...
CVE-2020-15083MEDIUM6.1In PrestaShop from version 1.7.0.0 and before version 1.7.6.6, if a target sends a corrupted file, it leads to a reflect...
CVE-2020-15081MEDIUM5.3In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The proble...
CVE-2020-15080MEDIUM5.3In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and othe...
CVE-2020-15079MEDIUM5.4In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module ...
CVE-2020-11074MEDIUM5.4In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick acce...
CVE-2020-13653MEDIUM6.1An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an ...
CVE-2020-2219MEDIUM5.4Jenkins Link Column Plugin 1.0 and earlier does not filter URLs of links created by users with View/Configure permission...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now