2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-29536MEDIUM4.3Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker w...
CVE-2020-29535MEDIUM5.4Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could p...
CVE-2020-29005HIGH7.5The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential ...
CVE-2020-29004HIGH8.8The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore ...
CVE-2020-28406MEDIUM6.5An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori...
CVE-2020-28405HIGH8.8An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori...
CVE-2020-28404MEDIUM6.5An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori...
CVE-2020-28403HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an...
CVE-2020-28402HIGH8.8An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori...
CVE-2020-28401MEDIUM6.5An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori...
CVE-2020-8585MEDIUM5.5OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorize...
CVE-2020-36115MEDIUM5.4Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf ...
CVE-2020-35754HIGH7.2OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequentl...
CVE-2020-35517HIGH8.2A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a...
CVE-2020-1725MEDIUM5.4A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changi...
CVE-2020-1723MEDIUM6.1A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbi...
CVE-2020-26272MEDIUM6.5The Electron framework lets users write cross-platform desktop applications using JavaScript, HTML and CSS. In versions ...
CVE-2020-4888HIGH8.8IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary com...
CVE-2020-4682CRITICAL9.8IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, ca...
CVE-2020-13569HIGH8.8A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0...
CVE-2020-5626HIGH8.8Logstorage version 8.0.0 and earlier, and ELC Analytics version 3.0.0 and earlier allow remote attackers to execute arbi...
CVE-2020-35124CRITICAL9.6A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inj...
CVE-2020-25785CRITICAL9.8An issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15....
CVE-2020-25784CRITICAL9.8An issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15....
CVE-2020-25783CRITICAL9.8An issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15....

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now