2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-10935MEDIUM5.4Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover.
CVE-2020-5293MEDIUM6.5In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations...
CVE-2020-5288MEDIUM6.5"In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The p...
CVE-2020-5287MEDIUM6.5In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is...
CVE-2020-5286MEDIUM6.1In PrestaShop between versions 1.7.4.0 and 1.7.6.5, there is a reflected XSS when uploading a wrong file. The problem is...
CVE-2020-5285MEDIUM6.1In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is a reflected XSS with `back` parameter. The problem is fixed...
CVE-2020-5279MEDIUM6.5In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for ...
CVE-2020-5278MEDIUM6.1In PrestaShop between versions 1.5.4.0 and 1.7.6.5, there is a reflected XSS on Exception page The problem is fixed in 1...
CVE-2020-5276MEDIUM6.1In PrestaShop between versions 1.7.1.0 and 1.7.6.5, there is a reflected XSS on AdminCarts page with `cartBox` parameter...
CVE-2020-5272MEDIUM6.1In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is a reflected XSS on Search page with `alias` and `search` pa...
CVE-2020-5271MEDIUM6.1In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters i...
CVE-2020-5270MEDIUM6.1In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts ...
CVE-2020-5269MEDIUM6.1In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feat...
CVE-2020-5265MEDIUM6.1In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminAttributesGroups page. The problem ...
CVE-2020-5264MEDIUM6.1In PrestaShop before version 1.7.6.5, there is a reflected XSS while running the security compromised page. It allows an...
CVE-2020-11888MEDIUM6.1python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example,...
CVE-2020-11930MEDIUM6.1The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflan...
CVE-2020-11887MEDIUM6.1svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document.
CVE-2020-5737MEDIUM5.4Stored XSS in Tenable.Sc before 5.14.0 could allow an authenticated remote attacker to craft a request to execute arbitr...
CVE-2020-5733MEDIUM6.1In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login pag...
CVE-2020-5732MEDIUM6.1In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page...
CVE-2020-5731MEDIUM6.1In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting.
CVE-2020-5730MEDIUM6.1In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.
CVE-2020-5729MEDIUM6.1In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which...
CVE-2020-5728MEDIUM6.1OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (suc...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now