2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-20597MEDIUM6.1A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10...
CVE-2020-20595MEDIUM6.5A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/...
CVE-2020-20426MEDIUM6.1S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave....
CVE-2020-20425MEDIUM6.1S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function...
CVE-2020-19770MEDIUM5.4A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to stea...
CVE-2020-35216MEDIUM5.9An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages.
CVE-2020-35215MEDIUM6.5An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distribu...
CVE-2020-35210MEDIUM6.5A vulnerability in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via a Raft session flooding attack ...
CVE-2020-18985MEDIUM6.1An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any...
CVE-2020-18984MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Col...
CVE-2020-19042MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in zzcms 2019 XSS via a modify action in user/adv.php.
CVE-2020-4496MEDIUM5.9The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent...
CVE-2020-16155MEDIUM6.5The CPAN::Checksums package 2.12 for Perl does not uniquely define signed data.
CVE-2020-12890MEDIUM6.7Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with...
CVE-2020-19683MEDIUM5.4A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.
CVE-2020-22421MEDIUM6.174CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&k...
CVE-2020-27356MEDIUM5.4The debug-meta-data plugin 1.1.2 for WordPress allows XSS.
CVE-2020-19611MEDIUM6.1Cross Site Scripting (XSS) in redirect module of Racktables version 0.21.2, allows an attacker to inject arbitrary web s...
CVE-2020-27413MEDIUM4.2An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext user...
CVE-2020-36135MEDIUM6.5AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c.
CVE-2020-36134MEDIUM6.5AOM v2.0.1 was discovered to contain a segmentation violation via the component aom_dsp/x86/obmc_sad_avx2.c.
CVE-2020-36130MEDIUM6.5AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component av1/av1_dx_iface.c.
CVE-2020-27414MEDIUM5.9Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to inform...
CVE-2020-35037MEDIUM6.1The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing the...
CVE-2020-22719MEDIUM5.4Shimo Document v2.0.1 contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary we...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now