2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-0058MEDIUM4.4In l2c_rcv_acl_data of l2c_main.cc, there is a possible out of bounds read due to an incorrect bounds check. This could ...
CVE-2020-0044MEDIUM4.4In set_nonce of fpc_ta_qc_auth.c, there is a possible out of bounds read due to a missing bounds check. This could lead ...
CVE-2020-0043MEDIUM4.4In authorize_enrol of fpc_ta_hw_auth.c, there is a possible out of bounds read due to a missing bounds check. This could...
CVE-2020-0042MEDIUM4.4In fpc_ta_hw_auth_unwrap_key of fpc_ta_hw_auth_qsee.c, there is a possible out of bounds read due to a missing bounds ch...
CVE-2020-0035MEDIUM5.5In query of TelephonyProvider.java, there is a possible access to SIM card info due to a missing permission check. This ...
CVE-2020-0031MEDIUM5In triggerAugmentedAutofillLocked and related functions of Session.java, it is possible for Augmented Autofill to displa...
CVE-2020-0012MEDIUM6.7In fpc_ta_pn_get_unencrypted_image of fpc_ta_pn.c, there is a possible out of bounds write due to a missing bounds check...
CVE-2020-0011MEDIUM6.7In get_auth_result of fpc_ta_hw_auth.c, there is a possible out of bounds write due to a missing bounds check. This coul...
CVE-2020-0010MEDIUM6.7In fpc_ta_get_build_info of fpc_ta_kpi.c, there is a possible out of bounds write due to a missing bounds check. This co...
CVE-2020-9440MEDIUM6.1A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to r...
CVE-2020-4162MEDIUM5.4IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2020-10251MEDIUM5.5In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the ReadHEICImageByID function in coders\heic.c....
CVE-2020-10249MEDIUM5.3BWA DiREX-Pro 1.2181 devices allow full path disclosure via an invalid name array parameter to val_soft.php3.
CVE-2020-10247MEDIUM6.1MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_...
CVE-2020-10246MEDIUM6.1MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.
CVE-2020-10192MEDIUM6.1An issue was discovered in Munkireport before 5.3.0.3923. An unauthenticated actor can send a custom XSS payload through...
CVE-2020-10191MEDIUM5.4An issue was discovered in MunkiReport before 5.3.0. An authenticated actor can send a custom XSS payload through the /m...
CVE-2020-4084MEDIUM5.4HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed ar...
CVE-2020-9517MEDIUM5.4There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Co...
CVE-2020-9386MEDIUM4.3In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed t...
CVE-2020-2157MEDIUM4.3Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configurat...
CVE-2020-2156MEDIUM4.3Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration ...
CVE-2020-2155MEDIUM5.3Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global...
CVE-2020-2154MEDIUM5.5Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configur...
CVE-2020-2153MEDIUM4.3Jenkins Backlog Plugin 2.4 and earlier transmits configured credentials in plain text as part of job configuration forms...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now