2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13248 | MEDIUM | 5.4 | 0.6% | Jun 24, 2020 | BooleBox Secure File Sharing Utility before 4.2.3.0 allows stored XSS via a crafted avatar field within My Account JSON ... |
| CVE-2020-15015 | MEDIUM | 6.1 | 0.7% | Jun 24, 2020 | The FileExplorer component in GleamTech FileUltimate 6.1.5.0 allows XSS via an SVG document. |
| CVE-2020-14018 | MEDIUM | 6.1 | 0.9% | Jun 24, 2020 | An issue was discovered in Navigate CMS 2.9 r1433. There is a stored XSS vulnerability that is executed on the page to v... |
| CVE-2020-14016 | MEDIUM | 5.3 | 1.6% | Jun 24, 2020 | An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by ... |
| CVE-2020-14014 | MEDIUM | 5.4 | 0.6% | Jun 24, 2020 | An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not... |
| CVE-2020-13483 | MEDIUM | 6.1 | 4.5% | Jun 24, 2020 | The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/... |
| CVE-2020-4413 | MEDIUM | 5.9 | 1.2% | Jun 24, 2020 | IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to ... |
| CVE-2020-4342 | MEDIUM | 5.3 | 1.1% | Jun 24, 2020 | IBM Security Secret Server 10.7 could disclose sensitive information included in installation files to an unauthorized u... |
| CVE-2020-4341 | MEDIUM | 5.3 | 1.4% | Jun 24, 2020 | IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical ... |
| CVE-2020-4327 | MEDIUM | 5.3 | 1.1% | Jun 24, 2020 | IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical ... |
| CVE-2020-4323 | MEDIUM | 6.1 | 0.7% | Jun 24, 2020 | IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2020-4322 | MEDIUM | 4.3 | 1.0% | Jun 24, 2020 | IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading... |
| CVE-2020-14007 | MEDIUM | 5.4 | 1.1% | Jun 24, 2020 | Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an a... |
| CVE-2020-14006 | MEDIUM | 5.4 | 1.1% | Jun 24, 2020 | Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible ... |
| CVE-2020-15018 | MEDIUM | 6.5 | 0.9% | Jun 24, 2020 | playSMS through 1.4.3 is vulnerable to session fixation. |
| CVE-2020-12866 | MEDIUM | 5.7 | 1.0% | Jun 24, 2020 | A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network ... |
| CVE-2020-12864 | MEDIUM | 4.3 | 1.2% | Jun 24, 2020 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as... |
| CVE-2020-12863 | MEDIUM | 4.3 | 1.0% | Jun 24, 2020 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as... |
| CVE-2020-12862 | MEDIUM | 4.3 | 1.1% | Jun 24, 2020 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as... |
| CVE-2020-15011 | MEDIUM | 4.3 | 1.9% | Jun 24, 2020 | GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page. |
| CVE-2020-15006 | MEDIUM | 5.4 | 0.5% | Jun 24, 2020 | Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php. |
| CVE-2020-10278 | MEDIUM | 4.6 | 1.0% | Jun 24, 2020 | The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings suc... |
| CVE-2020-10277 | MEDIUM | 6.4 | 0.4% | Jun 24, 2020 | There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of se... |
| CVE-2020-5345 | MEDIUM | 5.4 | 0.7% | Jun 23, 2020 | Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions p... |
| CVE-2020-14976 | MEDIUM | 5.5 | 0.5% | Jun 23, 2020 | GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary fi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now