2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-16255MEDIUM6.1ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'
CVE-2020-35749HIGH7.7Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2...
CVE-2020-35748MEDIUM5.4Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37...
CVE-2020-26414MEDIUM6.5An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is wr...
CVE-2020-35733HIGH7.5An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certif...
CVE-2020-35582MEDIUM5.4A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitr...
CVE-2020-35581MEDIUM5.4A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitr...
CVE-2020-27220HIGH8.8The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to r...
CVE-2020-27219MEDIUM6.1In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API...
CVE-2020-6572HIGH8.8Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a...
CVE-2020-29495CRITICAL10DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A ...
CVE-2020-29494HIGH8.7Dell EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a Path Traversal Vulnerability in PDM. A remote user could po...
CVE-2020-29493CRITICAL9.8DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote u...
CVE-2020-16046MEDIUM6.1Script injection in iOSWeb in Google Chrome on iOS prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary...
CVE-2020-16045CRITICAL9.6Use after Free in Payments in Google Chrome on Android prior to 87.0.4280.66 allowed a remote attacker who had compromis...
CVE-2020-6777MEDIUM4.8A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAE...
CVE-2020-6776HIGH8.8A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAE...
CVE-2020-29587MEDIUM5.4SimplCommerce 1.0.0-rc uses the Bootbox.js library, which allows creation of programmatic dialog boxes using Bootstrap m...
CVE-2020-29019MEDIUM5.3A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow a remote,...
CVE-2020-29018HIGH8.8A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the co...
CVE-2020-29017HIGH8.8An OS command injection vulnerability in FortiDeceptor 3.1.0, 3.0.1, 3.0.0 may allow a remote authenticated attacker to ...
CVE-2020-29016CRITICAL9.8A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauth...
CVE-2020-29015CRITICAL9.8A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauth...
CVE-2020-27368MEDIUM5.5Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /ic...
CVE-2020-26733MEDIUM5.4Cross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now