2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-7451MEDIUM5.3In FreeBSD 12.1-STABLE before r358739, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r358740, and 11.3-RELEASE...
CVE-2020-12430MEDIUM6.5An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A...
CVE-2020-9482MEDIUM6.5If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Regi...
CVE-2020-4329MEDIUM4.3IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allow a remote, authenti...
CVE-2020-1774MEDIUM4.9When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore ...
CVE-2020-10944MEDIUM5.4HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a ...
CVE-2020-10094MEDIUM5.4A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x befo...
CVE-2020-10093MEDIUM5.4A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
CVE-2020-12286MEDIUM4.3In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. Fo...
CVE-2020-5570MEDIUM5.4Cross-site scripting vulnerability in Sales Force Assistant version 11.2.48 and earlier allows remote authenticated atta...
CVE-2020-5568MEDIUM6.1Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 5.0.0 allows remote attackers to inject arbitrary web scrip...
CVE-2020-5566MEDIUM4.3Improper authorization vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to alter the...
CVE-2020-5565MEDIUM4.3Improper input validation vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows a remote authenticated attacker to alter...
CVE-2020-5564MEDIUM6.1Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to inject arbitrary web scri...
CVE-2020-5563MEDIUM5.3Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in the aff...
CVE-2020-5562MEDIUM4.9Server-side request forgery (SSRF) vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows a remote attacker with an admini...
CVE-2020-1722MEDIUM5.3A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to...
CVE-2020-1880MEDIUM5.5Huawei smartphone Lion-AL00C with versions earlier than 10.0.0.205(C00E202R7P2) have a denial of service vulnerability. ...
CVE-2020-9072MEDIUM6.7Huawei OSD product with versions earlier than OSD_uwp_9.0.32.0 have a local privilege escalation vulnerability. An authe...
CVE-2020-1845MEDIUM6.7Huawei PCManager product with versions earlier than 10.0.5.53 have a local privilege escalation vulnerability. An authen...
CVE-2020-11822MEDIUM6.1In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus...
CVE-2020-11821MEDIUM5.3In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hash...
CVE-2020-11415MEDIUM4.9An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can r...
CVE-2020-9489MEDIUM5.5A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can a...
CVE-2020-12272MEDIUM5.3OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now