2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-11883MEDIUM5.3In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpect...
CVE-2020-0077MEDIUM4.4In authorize_enroll of the FPC IRIS TrustZone app, there is a possible out of bounds read due to a missing bounds check....
CVE-2020-0076MEDIUM6.7In get_auth_result of the FPC IRIS TrustZone app, there is a possible out of bounds write due to a missing bounds check....
CVE-2020-0075MEDIUM4.4In set_shared_key of the FPC IRIS TrustZone app, there is a possible out of bounds read due to a missing bounds check. T...
CVE-2020-0068MEDIUM4.4In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds read due to an integer overflow. This ...
CVE-2020-0067MEDIUM4.4In f2fs_xattr_generic_list of xattr.c, there is a possible out of bounds read due to a missing bounds check. This could ...
CVE-2020-7084MEDIUM5.5A NULL pointer dereference vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of servi...
CVE-2020-7083MEDIUM6.5An intager overflow vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of service of t...
CVE-2020-11880MEDIUM6.5An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." paramete...
CVE-2020-11879MEDIUM6.5An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." pa...
CVE-2020-5294MEDIUM5.4PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflected XSS with social networks fields The problem is ...
CVE-2020-5273MEDIUM5.4In PrestaShop module ps_linklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fix...
CVE-2020-5266MEDIUM5.4In the ps_link module for PrestaShop before version 3.1.0, there is a stored XSS when you create or edit a link list blo...
CVE-2020-7113MEDIUM4.9A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to inte...
CVE-2020-7110MEDIUM4.8ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administr...
CVE-2020-2177MEDIUM4.3Jenkins Copr Plugin 0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where t...
CVE-2020-11823MEDIUM5.4In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit pag...
CVE-2020-11814MEDIUM5.4A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users ...
CVE-2020-11813MEDIUM5.4In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the configuration page via the copyright text input. Thus, ...
CVE-2020-11007MEDIUM6.5In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated ...
CVE-2020-4338MEDIUM5.5IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras...
CVE-2020-4260MEDIUM4.3IBM UrbanCode Deploy (UCD) 7.0.5 could allow a user with special permissions to obtain sensitive information via generic...
CVE-2020-5721MEDIUM5.5MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the ...
CVE-2020-3261MEDIUM6.5A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated,...
CVE-2020-3260MEDIUM6.5A vulnerability in Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to caus...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now