2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-13248MEDIUM5.4BooleBox Secure File Sharing Utility before 4.2.3.0 allows stored XSS via a crafted avatar field within My Account JSON ...
CVE-2020-15015MEDIUM6.1The FileExplorer component in GleamTech FileUltimate 6.1.5.0 allows XSS via an SVG document.
CVE-2020-14018MEDIUM6.1An issue was discovered in Navigate CMS 2.9 r1433. There is a stored XSS vulnerability that is executed on the page to v...
CVE-2020-14016MEDIUM5.3An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by ...
CVE-2020-14014MEDIUM5.4An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not...
CVE-2020-13483MEDIUM6.1The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/...
CVE-2020-4413MEDIUM5.9IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to ...
CVE-2020-4342MEDIUM5.3IBM Security Secret Server 10.7 could disclose sensitive information included in installation files to an unauthorized u...
CVE-2020-4341MEDIUM5.3IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical ...
CVE-2020-4327MEDIUM5.3IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical ...
CVE-2020-4323MEDIUM6.1IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2020-4322MEDIUM4.3IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading...
CVE-2020-14007MEDIUM5.4Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an a...
CVE-2020-14006MEDIUM5.4Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible ...
CVE-2020-15018MEDIUM6.5playSMS through 1.4.3 is vulnerable to session fixation.
CVE-2020-12866MEDIUM5.7A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network ...
CVE-2020-12864MEDIUM4.3An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as...
CVE-2020-12863MEDIUM4.3An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as...
CVE-2020-12862MEDIUM4.3An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as...
CVE-2020-15011MEDIUM4.3GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
CVE-2020-15006MEDIUM5.4Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.
CVE-2020-10278MEDIUM4.6The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings suc...
CVE-2020-10277MEDIUM6.4There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of se...
CVE-2020-5345MEDIUM5.4Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions p...
CVE-2020-14976MEDIUM5.5GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary fi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now