2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10935 | MEDIUM | 5.4 | 0.7% | Apr 20, 2020 | Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover. |
| CVE-2020-5293 | MEDIUM | 6.5 | 0.7% | Apr 20, 2020 | In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations... |
| CVE-2020-5288 | MEDIUM | 6.5 | 0.7% | Apr 20, 2020 | "In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The p... |
| CVE-2020-5287 | MEDIUM | 6.5 | 0.7% | Apr 20, 2020 | In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is... |
| CVE-2020-5286 | MEDIUM | 6.1 | 0.7% | Apr 20, 2020 | In PrestaShop between versions 1.7.4.0 and 1.7.6.5, there is a reflected XSS when uploading a wrong file. The problem is... |
| CVE-2020-5285 | MEDIUM | 6.1 | 0.8% | Apr 20, 2020 | In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is a reflected XSS with `back` parameter. The problem is fixed... |
| CVE-2020-5279 | MEDIUM | 6.5 | 0.8% | Apr 20, 2020 | In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for ... |
| CVE-2020-5278 | MEDIUM | 6.1 | 0.8% | Apr 20, 2020 | In PrestaShop between versions 1.5.4.0 and 1.7.6.5, there is a reflected XSS on Exception page The problem is fixed in 1... |
| CVE-2020-5276 | MEDIUM | 6.1 | 0.8% | Apr 20, 2020 | In PrestaShop between versions 1.7.1.0 and 1.7.6.5, there is a reflected XSS on AdminCarts page with `cartBox` parameter... |
| CVE-2020-5272 | MEDIUM | 6.1 | 0.8% | Apr 20, 2020 | In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is a reflected XSS on Search page with `alias` and `search` pa... |
| CVE-2020-5271 | MEDIUM | 6.1 | 0.8% | Apr 20, 2020 | In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters i... |
| CVE-2020-5270 | MEDIUM | 6.1 | 0.8% | Apr 20, 2020 | In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts ... |
| CVE-2020-5269 | MEDIUM | 6.1 | 0.8% | Apr 20, 2020 | In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feat... |
| CVE-2020-5265 | MEDIUM | 6.1 | 0.7% | Apr 20, 2020 | In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminAttributesGroups page. The problem ... |
| CVE-2020-5264 | MEDIUM | 6.1 | 0.7% | Apr 20, 2020 | In PrestaShop before version 1.7.6.5, there is a reflected XSS while running the security compromised page. It allows an... |
| CVE-2020-11888 | MEDIUM | 6.1 | 1.9% | Apr 20, 2020 | python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example,... |
| CVE-2020-11930 | MEDIUM | 6.1 | 4.5% | Apr 20, 2020 | The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflan... |
| CVE-2020-11887 | MEDIUM | 6.1 | 0.7% | Apr 17, 2020 | svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document. |
| CVE-2020-5737 | MEDIUM | 5.4 | 0.6% | Apr 17, 2020 | Stored XSS in Tenable.Sc before 5.14.0 could allow an authenticated remote attacker to craft a request to execute arbitr... |
| CVE-2020-5733 | MEDIUM | 6.1 | 1.2% | Apr 17, 2020 | In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login pag... |
| CVE-2020-5732 | MEDIUM | 6.1 | 1.2% | Apr 17, 2020 | In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page... |
| CVE-2020-5731 | MEDIUM | 6.1 | 1.1% | Apr 17, 2020 | In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting. |
| CVE-2020-5730 | MEDIUM | 6.1 | 1.1% | Apr 17, 2020 | In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting. |
| CVE-2020-5729 | MEDIUM | 6.1 | 1.1% | Apr 17, 2020 | In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which... |
| CVE-2020-5728 | MEDIUM | 6.1 | 1.1% | Apr 17, 2020 | OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (suc... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now