2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-11420MEDIUM6.5UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exp...
CVE-2020-12052MEDIUM6.1Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
CVE-2020-10997MEDIUM6.5Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may i...
CVE-2020-12270MEDIUM6.5React Native Bluetooth Scan in Bluezone 1.0.0 uses six-character alphanumeric IDs, which might make it easier for remote...
CVE-2020-6213MEDIUM6.1SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750,...
CVE-2020-6212MEDIUM5.4Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (version...
CVE-2020-12245MEDIUM6.1Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
CVE-2020-11013MEDIUM5Their is an information disclosure vulnerability in Helm from version 3.1.0 and before version 3.2.0. `lookup` is a Helm...
CVE-2020-7134MEDIUM6.5A remote access to sensitive data vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2...
CVE-2020-1741MEDIUM5.9A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified...
CVE-2020-6827MEDIUM4.7When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could...
CVE-2020-4267MEDIUM6.5IBM MQ and MQ Appliance 8.0, 9.1 LTS, and 9.1 CD could allow an authenticated user cause a denial of service due to a me...
CVE-2020-12137MEDIUM6.1GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior ma...
CVE-2020-12063MEDIUM5.3A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homog...
CVE-2020-12135MEDIUM5.5bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular...
CVE-2020-12132MEDIUM6.1Fifthplay S.A.M.I before 2019.3_HP2 allows unauthenticated stored XSS via a POST request.
CVE-2020-12131MEDIUM6.1The AirDisk Pro app 5.5.3 for iOS allows XSS via the devicename parameter (shown next to the UI logo).
CVE-2020-12130MEDIUM6.1The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function.
CVE-2020-12129MEDIUM6.1The AirDisk Pro app 5.5.3 for iOS allows XSS via the createFolder parameter of the Create Folder function.
CVE-2020-8798MEDIUM5.5httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the...
CVE-2020-5866MEDIUM5.5In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to ch...
CVE-2020-5865MEDIUM4.8In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over une...
CVE-2020-8797MEDIUM6.7Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call ...
CVE-2020-7132MEDIUM5.4A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely...
CVE-2020-12113MEDIUM6.1BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now