2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-10560MEDIUM5.9An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak crypto...
CVE-2020-10955MEDIUM6.5GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized use...
CVE-2020-10952MEDIUM6.5GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.
CVE-2020-8552MEDIUM4.3The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be v...
CVE-2020-8551MEDIUM6.5The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a d...
CVE-2020-7918MEDIUM5.4An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read an...
CVE-2020-1771MEDIUM5.4Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When age...
CVE-2020-1770MEDIUM4.3Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue af...
CVE-2020-1769MEDIUM4.3In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be co...
CVE-2020-10510MEDIUM6.5Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. Afte...
CVE-2020-10509MEDIUM6.1Sunnet eHRD, a human training and development management system, contains vulnerability of Cross-Site Scripting (XSS), a...
CVE-2020-9468MEDIUM4.3The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do n...
CVE-2020-9467MEDIUM5.4Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
CVE-2020-9065MEDIUM5.5Huawei smart phone Taurus-AL00B with versions earlier than 10.0.0.203(C00E201R7P2) have a use-after-free (UAF) vulnerabi...
CVE-2020-6999MEDIUM6.5In Moxa EDS-G516E Series firmware, Version 5.2 or lower, some of the parameters in the setting pages do not ensure text ...
CVE-2020-5340MEDIUM4.8RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security...
CVE-2020-5339MEDIUM4.8RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security...
CVE-2020-8923MEDIUM6.1An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an atta...
CVE-2020-8910MEDIUM6.5A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker ...
CVE-2020-10966MEDIUM6.5In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header ...
CVE-2020-6813MEDIUM5.3When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block cou...
CVE-2020-6812MEDIUM5.3The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's A...
CVE-2020-6810MEDIUM4.3After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification th...
CVE-2020-6808MEDIUM6.5When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML doc...
CVE-2020-9520MEDIUM5.4A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerabil...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now