2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-3884MEDIUM6.1An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attac...
CVE-2020-3881MEDIUM5.5A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A local user ...
CVE-2020-10864MEDIUM6.5An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Servi...
CVE-2020-11457MEDIUM5.4pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full n...
CVE-2020-11456MEDIUM5.4LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and applicati...
CVE-2020-6753MEDIUM6.1The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-202...
CVE-2020-5392MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings...
CVE-2020-7263MEDIUM6.7Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current vers...
CVE-2020-7066MEDIUM4.3In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-suppli...
CVE-2020-7064MEDIUM5.4In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data...
CVE-2020-11445MEDIUM5.3TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive informatio...
CVE-2020-11441MEDIUM6.1phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF s...
CVE-2020-4240MEDIUM6.5IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An ...
CVE-2020-4239MEDIUM5.3IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow a remote attacker to obtain sensitive information when a ...
CVE-2020-4236MEDIUM6.5IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow an authenticated user to cause a denial of service due to...
CVE-2020-4235MEDIUM5.4IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2020-9055MEDIUM5.4Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could al...
CVE-2020-5289MEDIUM6.5In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have...
CVE-2020-5284MEDIUM4.3Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access...
CVE-2020-11106MEDIUM6.1An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION...
CVE-2020-11104MEDIUM5.3An issue was discovered in USC iLab cereal through 1.3.0. Serialization of an (initialized) C/C++ long double variable i...
CVE-2020-5725MEDIUM5.9The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpo...
CVE-2020-5274MEDIUM5.4In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHa...
CVE-2020-5255MEDIUM4.3In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected version...
CVE-2020-7599MEDIUM6.5All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log Fi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now