2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-13964MEDIUM6.1An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows...
CVE-2020-13844MEDIUM5.5Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow un...
CVE-2020-4041MEDIUM6.1In Bolt CMS before version 3.7.1, the filename of uploaded files was vulnerable to stored XSS. It is not possible to inj...
CVE-2020-4040MEDIUM4.3Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be gen...
CVE-2020-10754MEDIUM4.3It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-p...
CVE-2020-8954MEDIUM5.4OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manip...
CVE-2020-13696MEDIUM4.4An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient...
CVE-2020-12049MEDIUM5.5An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file d...
CVE-2020-1775MEDIUM4.3BCC recipients in mails sent from OTRS are visible in article detail on external interface. This issue affects OTRS: 8.0...
CVE-2020-12803MEDIUM6.5ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be subm...
CVE-2020-12802MEDIUM5.3LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote ...
CVE-2020-7676MEDIUM5.4angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code in...
CVE-2020-13904MEDIUM5.5FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavf...
CVE-2020-13897MEDIUM6.1HESK before 3.1.10 allows reflected XSS.
CVE-2020-13890MEDIUM5.4The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.
CVE-2020-13889MEDIUM5.4showAlert() in the administration panel in Bludit 3.12.0 allows XSS.
CVE-2020-13883MEDIUM6.7In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Manage...
CVE-2020-13865MEDIUM5.4The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author...
CVE-2020-13864MEDIUM5.4The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can...
CVE-2020-11696MEDIUM6.1In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (com...
CVE-2020-11697MEDIUM6.1In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (commu...
CVE-2020-13870MEDIUM5.4An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.
CVE-2020-13869MEDIUM5.4An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name.
CVE-2020-13868MEDIUM6.5An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.
CVE-2020-13867MEDIUM5.5Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup fil...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now