2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-4070MEDIUM5.4In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A...
CVE-2020-4060MEDIUM5In LoRa Basics Station before 2.0.4, there is a Use After Free vulnerability that leads to memory corruption. This bug i...
CVE-2020-13888MEDIUM5.4Kordil EDMS through 2.2.60rc3 allows stored XSS in users_edit.php, users_management_edit.php, and user_management.php.
CVE-2020-14202MEDIUM6.1WebFOCUS Business Intelligence 8.0 (SP6) was prone to XSS via arbitrary URL parameters.
CVE-2020-7262MEDIUM5.5Improper Access Control vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.10.0 allows local users to view...
CVE-2020-14962MEDIUM5.4Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inj...
CVE-2020-14961MEDIUM5.3Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.
CVE-2020-14959MEDIUM5.4Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject a...
CVE-2020-14958MEDIUM6.5In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.
CVE-2020-14954MEDIUM5.9Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When...
CVE-2020-13264MEDIUM5.3Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view...
CVE-2020-13276MEDIUM4.3User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/E...
CVE-2020-13265MEDIUM5.3User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification
CVE-2020-13262MEDIUM6.1Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially craft...
CVE-2020-10750MEDIUM5.5Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when t...
CVE-2020-9495MEDIUM5.3Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute...
CVE-2020-8167MEDIUM6.5A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong d...
CVE-2020-13277MEDIUM6.5An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later...
CVE-2020-14927MEDIUM4.8Navigate CMS 2.9 allows XSS via the Alias or Real URL field of the "Web Sites > Create > Aliases > Add" screen.
CVE-2020-14926MEDIUM5.4CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.
CVE-2020-14475MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web ...
CVE-2020-13961MEDIUM6.5Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are st...
CVE-2020-4297MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerabi...
CVE-2020-4295MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerabi...
CVE-2020-4281MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerabi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now