2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35721MEDIUM5.4Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...
CVE-2020-35720MEDIUM5.4Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first...
CVE-2020-35719MEDIUM6.1Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...
CVE-2020-35206MEDIUM6.1Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious...
CVE-2020-35205CRITICAL9.8Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attacker...
CVE-2020-35204MEDIUM6.1Reflected XSS in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via...
CVE-2020-35203MEDIUM6.1Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious...
CVE-2020-5147MEDIUM5.3SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to ...
CVE-2020-5146HIGH7.2A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection usi...
CVE-2020-4733MEDIUM5.4IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2020-4697MEDIUM5.4IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2020-4691MEDIUM5.4IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2020-4544MEDIUM4.3IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical err...
CVE-2020-4487MEDIUM4.3IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical err...
CVE-2020-5022MEDIUM5.3IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which ca...
CVE-2020-5021MEDIUM4.4IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a l...
CVE-2020-5020MEDIUM6.1IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking action of the victi...
CVE-2020-5019MEDIUM6.5IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of...
CVE-2020-5018HIGH7.5IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of suc...
CVE-2020-5017MEDIUM5.5IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to information beyond their inte...
CVE-2020-26186MEDIUM6.8Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local att...
CVE-2020-16043HIGH8.8Insufficient data validation in networking in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to bypass d...
CVE-2020-16042MEDIUM6.5Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive...
CVE-2020-16041HIGH8.1Out of bounds read in networking in Google Chrome prior to 87.0.4280.88 allowed a remote attacker who had compromised th...
CVE-2020-16040MEDIUM6.5Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now