2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-11508MEDIUM5.4An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permiss...
CVE-2020-11611MEDIUM6.1An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the ...
CVE-2020-9514MEDIUM6.5An issue was discovered in the IMPress for IDX Broker plugin before 2.6.2 for WordPress. wrappers.php allows a logged-in...
CVE-2020-11609MEDIUM4.3An issue was discovered in the stv06xx subsystem in the Linux kernel before 5.6.1. drivers/media/usb/gspca/stv06xx/stv06...
CVE-2020-11516MEDIUM5.4Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minim...
CVE-2020-11515MEDIUM6.1The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that red...
CVE-2020-11512MEDIUM5.4Stored XSS in the IMPress for IDX Broker WordPress plugin before 2.6.2 allows authenticated attackers with minimal (subs...
CVE-2020-5302MEDIUM6.5MH-WikiBot (an IRC Bot for interacting with the Miraheze API), had a bug that allowed any unprivileged user to access th...
CVE-2020-7618MEDIUM5.3sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties ...
CVE-2020-7616MEDIUM5.3express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tri...
CVE-2020-11608MEDIUM4.3An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NULL pointer dereferenc...
CVE-2020-6171MEDIUM6.1A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote at...
CVE-2020-2176MEDIUM5.4Multiple form validation endpoints in Jenkins useMango Runner Plugin 1.4 and earlier do not escape values received from ...
CVE-2020-2175MEDIUM5.4Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI...
CVE-2020-2174MEDIUM6.1Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation out...
CVE-2020-2173MEDIUM5.4Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports ser...
CVE-2020-2172MEDIUM6.5Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE...
CVE-2020-8096MEDIUM5.3Untrusted Search Path vulnerability in Bitdefender High-Level Antimalware SDK for Windows allows an attacker to load thi...
CVE-2020-11591MEDIUM5.3An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request a...
CVE-2020-11590MEDIUM5.3An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET requ...
CVE-2020-11588MEDIUM5.3An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET requ...
CVE-2020-11585MEDIUM4.3There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Us...
CVE-2020-5300MEDIUM5.3In Hydra (an OAuth2 Server and OpenID Certified™ OpenID Connect Provider written in Go), before version 1.4.0+oryOS.17, ...
CVE-2020-11102MEDIUM5.6hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not val...
CVE-2020-9473MEDIUM6.6The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 has a passwordless ftp ssh user. By using an exploit chain, a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now