2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-11017MEDIUM6.5In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condi...
CVE-2020-4490MEDIUM6.1IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote atta...
CVE-2020-4306MEDIUM5.4IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users ...
CVE-2020-5573MEDIUM4.6Android App 'kintone mobile for Android' 1.0.0 to 2.5 allows an attacker to obtain credential information registered in ...
CVE-2020-5572MEDIUM4.6Android App 'Mailwise for Android' 1.0.0 to 1.0.1 allows an attacker to obtain credential information registered in the ...
CVE-2020-11082MEDIUM6.1In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with...
CVE-2020-5357MEDIUM6Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File O...
CVE-2020-13660MEDIUM4.8CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
CVE-2020-13245MEDIUM5.9Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1....
CVE-2020-4419MEDIUM5.4IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2020-4249MEDIUM6.5IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticat...
CVE-2020-4244MEDIUM5.3IBM Security Identity Governance and Intelligence 5.2.6 could allow an unauthorized user to obtain sensitive information...
CVE-2020-4233MEDIUM5.3IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, c...
CVE-2020-4231MEDIUM6.5IBM Security Identity Governance and Intelligence 5.2.6 could allow an authenticated user to perform unauthorized comman...
CVE-2020-11949MEDIUM6.5testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXX...
CVE-2020-13645MEDIUM6.5In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the s...
CVE-2020-13644MEDIUM5.4An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax...
CVE-2020-8603MEDIUM6.1A cross-site scripting vulnerability (XSS) in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow a remot...
CVE-2020-13633MEDIUM6.1Fork before 5.8.3 allows XSS via navigation_title or title.
CVE-2020-13628MEDIUM6.1Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId...
CVE-2020-13627MEDIUM6.1Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId...
CVE-2020-10946MEDIUM6.1Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page par...
CVE-2020-10945MEDIUM4.3Centreon before 19.10.7 exposes Session IDs in server responses.
CVE-2020-13632MEDIUM5.5ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
CVE-2020-13631MEDIUM5.5SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c an...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now