2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14271MEDIUM6.1HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling ...
CVE-2020-14224CRITICAL9.8A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthentic...
CVE-2020-4080MEDIUM6.1HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of me...
CVE-2020-5803HIGH8.1Relative Path Traversal in Marvell QConvergeConsole GUI 5.5.0.74 allows a remote, authenticated attacker to delete arbit...
CVE-2020-27781HIGH7.1User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential pr...
CVE-2020-17520MEDIUM6.5In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verificat...
CVE-2020-13535HIGH7.8A privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker ca...
CVE-2020-11974CRITICAL9.8In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing my...
CVE-2020-13519HIGH8.8A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c402088 functionality of NZXT CAM 4.8.0. A ...
CVE-2020-13515HIGH8.8A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c40a148 functionality of NZXT CAM 4.8.0. A ...
CVE-2020-13514HIGH8.8A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CA...
CVE-2020-13513HIGH8.8A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CA...
CVE-2020-13512HIGH8.8A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CA...
CVE-2020-27687HIGH8.8ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send...
CVE-2020-26280HIGH8.9OpenSlides is a free, Web-based presentation and assembly system for managing and projecting agenda, motions, and electi...
CVE-2020-20300CRITICAL9.8SQL injection vulnerability in the wp_where function in WeiPHP 5.0.
CVE-2020-20299HIGH7.5WeiPHP 5.0 does not properly restrict access to pages, related to using POST.
CVE-2020-20298CRITICAL9.8Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 ...
CVE-2020-20285MEDIUM5.4There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php
CVE-2020-20277CRITICAL9.8There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server ver...
CVE-2020-20276CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10...
CVE-2020-26251MEDIUM4.7Open Zaak is a modern, open-source data- and services-layer to enable zaakgericht werken, a Dutch approach to case manag...
CVE-2020-4764MEDIUM6.5IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou...
CVE-2020-25901MEDIUM6.1Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious we...
CVE-2020-25495MEDIUM6.1A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote at...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now