2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-13673MEDIUM6.1The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the f...
CVE-2020-13672MEDIUM6.1Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting...
CVE-2020-13669MEDIUM6.1Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: D...
CVE-2020-13668MEDIUM6.1Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected...
CVE-2020-12966MEDIUM5.5AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypt...
CVE-2020-26208MEDIUM6.1JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedded in Jpeg images fro...
CVE-2020-36056MEDIUM5.4Beetel 777VR1-DI Hardware Version REV.1.01 Firmware Version V01.00.09_55 was discovered to contain a cross-site scriptin...
CVE-2020-19860MEDIUM6.5When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vu...
CVE-2020-28919MEDIUM5.4A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote att...
CVE-2020-25427MEDIUM5.5A Null pointer dereference vulnerability exits in MP4Box - GPAC version 0.8.0-rev177-g51a8ef874-master via the gf_isom_g...
CVE-2020-9061MEDIUM6.5Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 vers...
CVE-2020-9060MEDIUM6.5Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 ve...
CVE-2020-9059MEDIUM6.5Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resourc...
CVE-2020-10137MEDIUM6.5Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN...
CVE-2020-27428MEDIUM6.1A DOM-based cross-site scripting (XSS) vulnerability in Scratch-Svg-Renderer v0.2.0 allows attackers to execute arbitrar...
CVE-2020-23986MEDIUM6.1Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site sc...
CVE-2020-15933MEDIUM5.3A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail v...
CVE-2020-29292MEDIUM6.5iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or ...
CVE-2020-20946MEDIUM5.4Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&...
CVE-2020-20943MEDIUM4.3A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force v...
CVE-2020-35398MEDIUM5.3An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumera...
CVE-2020-3896MEDIUM5.5This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Catalina 10.15.4, Security Update...
CVE-2020-20605MEDIUM6.1Blog CMS v1.0 contains a cross-site scripting (XSS) vulnerability in the /controller/CommentAdminController.java compone...
CVE-2020-20600MEDIUM5.4MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=...
CVE-2020-20598MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitra...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now