2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-20597 | MEDIUM | 6.1 | 0.8% | Dec 22, 2021 | A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10... |
| CVE-2020-20595 | MEDIUM | 6.5 | 0.5% | Dec 22, 2021 | A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/... |
| CVE-2020-20426 | MEDIUM | 6.1 | 0.9% | Dec 22, 2021 | S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.... |
| CVE-2020-20425 | MEDIUM | 6.1 | 0.9% | Dec 22, 2021 | S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function... |
| CVE-2020-19770 | MEDIUM | 5.4 | 0.5% | Dec 21, 2021 | A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to stea... |
| CVE-2020-35216 | MEDIUM | 5.9 | 0.7% | Dec 16, 2021 | An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages. |
| CVE-2020-35215 | MEDIUM | 6.5 | 0.8% | Dec 16, 2021 | An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distribu... |
| CVE-2020-35210 | MEDIUM | 6.5 | 0.9% | Dec 16, 2021 | A vulnerability in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via a Raft session flooding attack ... |
| CVE-2020-18985 | MEDIUM | 6.1 | 0.7% | Dec 15, 2021 | An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any... |
| CVE-2020-18984 | MEDIUM | 6.1 | 0.8% | Dec 15, 2021 | A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Col... |
| CVE-2020-19042 | MEDIUM | 6.1 | 0.9% | Dec 13, 2021 | Cross Site Scripting (XSS) vulnerability exists in zzcms 2019 XSS via a modify action in user/adv.php. |
| CVE-2020-4496 | MEDIUM | 5.9 | 0.6% | Dec 13, 2021 | The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent... |
| CVE-2020-16155 | MEDIUM | 6.5 | 1.0% | Dec 13, 2021 | The CPAN::Checksums package 2.12 for Perl does not uniquely define signed data. |
| CVE-2020-12890 | MEDIUM | 6.7 | 0.3% | Dec 10, 2021 | Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with... |
| CVE-2020-19683 | MEDIUM | 5.4 | 0.6% | Dec 9, 2021 | A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php. |
| CVE-2020-22421 | MEDIUM | 6.1 | 0.8% | Dec 8, 2021 | 74CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&k... |
| CVE-2020-27356 | MEDIUM | 5.4 | 1.0% | Dec 7, 2021 | The debug-meta-data plugin 1.1.2 for WordPress allows XSS. |
| CVE-2020-19611 | MEDIUM | 6.1 | 0.6% | Dec 7, 2021 | Cross Site Scripting (XSS) in redirect module of Racktables version 0.21.2, allows an attacker to inject arbitrary web s... |
| CVE-2020-27413 | MEDIUM | 4.2 | 0.3% | Dec 7, 2021 | An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext user... |
| CVE-2020-36135 | MEDIUM | 6.5 | 1.4% | Dec 2, 2021 | AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c. |
| CVE-2020-36134 | MEDIUM | 6.5 | 1.1% | Dec 2, 2021 | AOM v2.0.1 was discovered to contain a segmentation violation via the component aom_dsp/x86/obmc_sad_avx2.c. |
| CVE-2020-36130 | MEDIUM | 6.5 | 1.4% | Dec 2, 2021 | AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component av1/av1_dx_iface.c. |
| CVE-2020-27414 | MEDIUM | 5.9 | 1.0% | Dec 2, 2021 | Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to inform... |
| CVE-2020-35037 | MEDIUM | 6.1 | 0.9% | Dec 1, 2021 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing the... |
| CVE-2020-22719 | MEDIUM | 5.4 | 0.5% | Nov 22, 2021 | Shimo Document v2.0.1 contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary we... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now