2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-0127MEDIUM6.5In AudioStream::decode of AudioGroup.cpp, there is a possible out of bounds read due to a missing bounds check. This cou...
CVE-2020-0126MEDIUM6.4In multiple functions in DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to l...
CVE-2020-0124MEDIUM6.7In markBootComplete of InstalldNativeService.cpp, there is a possible out of bounds write due to a missing bounds check....
CVE-2020-4380MEDIUM5.4IBM Workload Scheduler 9.3.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary...
CVE-2020-5592MEDIUM6.1Cross-site scripting vulnerability in Zenphoto versions prior to 1.5.7 allows remote attackers to inject an arbitrary Ja...
CVE-2020-13853MEDIUM5.4Artica Pandora FMS 7.44 has persistent XSS in the Messages feature.
CVE-2020-13998MEDIUM5.3Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on t...
CVE-2020-12714MEDIUM5.9An issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual A...
CVE-2020-5363MEDIUM6.7Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed ...
CVE-2020-5362MEDIUM4.4Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability ...
CVE-2020-13444MEDIUM6.5Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack...
CVE-2020-2033MEDIUM5.3When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can di...
CVE-2020-2023MEDIUM6.3Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can ...
CVE-2020-14012MEDIUM5.4scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker...
CVE-2020-14010MEDIUM6.1The Laborator Xenon theme 1.3 for WordPress allows Reflected XSS via the data/typeahead-generate.php q (aka name) parame...
CVE-2020-11798MEDIUM5.3A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before ...
CVE-2020-0121MEDIUM5.5In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead...
CVE-2020-0119MEDIUM5.3In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle att...
CVE-2020-0116MEDIUM5.5In checkSystemLocationAccess of LocationAccessPolicy.java, there is a possible bypass of user profile isolation due to a...
CVE-2020-0113MEDIUM5.5In sendCaptureResult of Camera3OutputUtils.cpp, there is a possible out of bounds read due to a use after free. This cou...
CVE-2020-7580MEDIUM6.7A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All...
CVE-2020-10755MEDIUM6.5An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-ci...
CVE-2020-13271MEDIUM6.1A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all p...
CVE-2020-13269MEDIUM6.1A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Edi...
CVE-2020-13268MEDIUM5.3A specially crafted request could be used to confirm the existence of files hosted on object storage services, without d...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now