2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-5750MEDIUM6.1Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-...
CVE-2020-5749MEDIUM5.4Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si...
CVE-2020-5748MEDIUM6.1Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-...
CVE-2020-5747MEDIUM5.4Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si...
CVE-2020-5746MEDIUM5.4Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si...
CVE-2020-5744MEDIUM4.9Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files...
CVE-2020-5743MEDIUM4.3Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadat...
CVE-2020-12679MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 befor...
CVE-2020-12448MEDIUM5.3GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.
CVE-2020-12687MEDIUM6.5An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin aut...
CVE-2020-12683MEDIUM5.4Katyshop2 before 2.12 has multiple stored XSS issues.
CVE-2020-12696MEDIUM6.1The iframe plugin before 4.5 for WordPress does not sanitize a URL.
CVE-2020-12692MEDIUM5.4An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check ...
CVE-2020-11727MEDIUM6.1A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordP...
CVE-2020-3329MEDIUM4.3A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Direc...
CVE-2020-3315MEDIUM5.3Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticate...
CVE-2020-3313MEDIUM6.1A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote...
CVE-2020-3311MEDIUM6.1A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated,...
CVE-2020-3310MEDIUM4.9A vulnerability in the XML parser code of Cisco Firepower Device Manager On-Box software could allow an authenticated, r...
CVE-2020-3308MEDIUM4.9A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow...
CVE-2020-3307MEDIUM5.3A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote...
CVE-2020-3301MEDIUM4.4Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software cou...
CVE-2020-3285MEDIUM5.8A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category functionality for Cisco F...
CVE-2020-3256MEDIUM4.9A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) Softwa...
CVE-2020-3253MEDIUM6.7A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authentica...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now