2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-15307MEDIUM6.1Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to...
CVE-2020-15085MEDIUM6.1In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the ...
CVE-2020-15412MEDIUM4.3An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding ...
CVE-2020-15401MEDIUM4.4IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious fl...
CVE-2020-15400MEDIUM4.3CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
CVE-2020-5588MEDIUM4.9Path traversal vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to obtain uninten...
CVE-2020-5587MEDIUM6.5Cybozu Garoon 4.0.0 to 5.0.1 allow remote authenticated attackers to obtain unintended information via unspecified vecto...
CVE-2020-5586MEDIUM4.8Cross-site scripting vulnerability in Cybozu Garoon 4.10.3 to 5.0.1 allows attacker with administrator rights to inject ...
CVE-2020-5585MEDIUM4.8Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to inject a...
CVE-2020-5583MEDIUM6.5Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to obtain unauthorized M...
CVE-2020-5582MEDIUM4.3Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to alter the data for th...
CVE-2020-5581MEDIUM6.5Path traversal vulnerability in Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to obtain unintended ...
CVE-2020-15393MEDIUM5.5In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebe...
CVE-2020-15389MEDIUM6.5jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and...
CVE-2020-15368MEDIUM5.5AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering ...
CVE-2020-4037MEDIUM5.4In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to se...
CVE-2020-15043MEDIUM6.5iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the...
CVE-2020-14145MEDIUM5.9The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm...
CVE-2020-14002MEDIUM5.9PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This ...
CVE-2020-13896MEDIUM5.3The web interface of Maipu MP1800X-50 7.5.3.14(R) devices allows remote attackers to obtain sensitive information via th...
CVE-2020-13657MEDIUM5.5An elevation of privilege vulnerability exists in Avast Free Antivirus and AVG AntiVirus Free before 20.4 due to imprope...
CVE-2020-14413MEDIUM6.1NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function at...
CVE-2020-14071MEDIUM6.1An issue was discovered in MK-AUTH 19.01. XSS vulnerabilities in admin and client scripts allow an attacker to execute a...
CVE-2020-14069MEDIUM6.8An issue was discovered in MK-AUTH 19.01. There are SQL injection issues in mkt/ PHP scripts, as demonstrated by arp.php...
CVE-2020-15319MEDIUM5.9Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now