2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-1793MEDIUM4.6There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient auth...
CVE-2020-1696MEDIUM5.4A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly san...
CVE-2020-10681MEDIUM5.4The Filemanager in CMS Made Simple 2.2.13 has stored XSS via a .pxd file, as demonstrated by m1_files[] to admin/modulei...
CVE-2020-9345MEDIUM6.5An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is poss...
CVE-2020-9344MEDIUM6.1Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations.
CVE-2020-9343MEDIUM6.5An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is poss...
CVE-2020-10670MEDIUM6.1The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the paramet...
CVE-2020-10668MEDIUM6.1The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in /home.jsp. ...
CVE-2020-10667MEDIUM6.1The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Stored XSS in /TemplateManag...
CVE-2020-5267MEDIUM4.8In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript lite...
CVE-2020-5262MEDIUM5.5In EasyBuild before version 4.1.2, the GitHub Personal Access Token (PAT) used by EasyBuild for the GitHub integration f...
CVE-2020-4205MEDIUM6.3IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, a...
CVE-2020-4203MEDIUM4.9IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could potentially disclose highly sensitive information to a privile...
CVE-2020-10365MEDIUM6.5LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the datab...
CVE-2020-7258MEDIUM4.8Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update all...
CVE-2020-7256MEDIUM4.8Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update all...
CVE-2020-10665MEDIUM6.7Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnost...
CVE-2020-9323MEDIUM5.3Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx.
CVE-2020-6976MEDIUM5.5Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited wh...
CVE-2020-4199MEDIUM4.3IBM Tivoli Netcool/OMNIbus 8.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute ma...
CVE-2020-9443MEDIUM6.1Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be expl...
CVE-2020-10659MEDIUM4.3Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validati...
CVE-2020-1720MEDIUM6.5A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization chec...
CVE-2020-10596MEDIUM5.4OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upl...
CVE-2020-10122MEDIUM6.5cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547).

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now