2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-4082MEDIUM5.4The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplie...
CVE-2020-5250MEDIUM6.3In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the ...
CVE-2020-8994MEDIUM6.8An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing t...
CVE-2020-10107MEDIUM5.4PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS, as demonstrated by the ExpenseItem or ExpenseCo...
CVE-2020-10105MEDIUM5.3An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS...
CVE-2020-10104MEDIUM4.3An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user ...
CVE-2020-10103MEDIUM5.4An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through t...
CVE-2020-10102MEDIUM5.3An issue was discovered in Zammad 3.0 through 3.2. The Forgot Password functionality is implemented in a way that would ...
CVE-2020-10100MEDIUM6.5An issue was discovered in Zammad 3.0 through 3.2. It allows for users to view ticket customer details associated with s...
CVE-2020-10099MEDIUM5.4An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through t...
CVE-2020-10098MEDIUM5.4An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through t...
CVE-2020-10097MEDIUM5.3An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal app...
CVE-2020-8660MEDIUM5.3CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) ...
CVE-2020-8664MEDIUM5.3CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same s...
CVE-2020-9371MEDIUM4.8Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php ...
CVE-2020-3193MEDIUM5.3A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthent...
CVE-2020-3192MEDIUM6.1A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthent...
CVE-2020-3190MEDIUM5.8A vulnerability in the IPsec packet processor of Cisco IOS XR Software could allow an unauthenticated remote attacker to...
CVE-2020-3185MEDIUM5.4A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an authen...
CVE-2020-3182MEDIUM4.3A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow ...
CVE-2020-3181MEDIUM6.5A vulnerability in the malware detection functionality in Cisco Advanced Malware Protection (AMP) in Cisco AsyncOS Softw...
CVE-2020-3176MEDIUM6.7A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on ...
CVE-2020-3164MEDIUM5.3A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco W...
CVE-2020-3157MEDIUM5.4A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2020-9364MEDIUM5.3An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now