2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-5251MEDIUM5.3In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the...
CVE-2020-10029MEDIUM5.5The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input ...
CVE-2020-5404MEDIUM5.9The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorr...
CVE-2020-4198MEDIUM5.4IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2020-4196MEDIUM5.4IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2020-8778MEDIUM5.4Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, ...
CVE-2020-8777MEDIUM5.4Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, ...
CVE-2020-8776MEDIUM5.4Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a ...
CVE-2020-5249MEDIUM6.5In Puma (RubyGem) before 4.3.3 and 3.12.4, if an application using Puma allows untrusted input in an early-hints header,...
CVE-2020-4292MEDIUM5.3IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 uses a cross-domain policy file that include...
CVE-2020-5539MEDIUM6.5GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote at...
CVE-2020-6798MEDIUM6.1If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when...
CVE-2020-6797MEDIUM4.3By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on ...
CVE-2020-6795MEDIUM6.5When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null poin...
CVE-2020-6794MEDIUM6.5If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passw...
CVE-2020-6793MEDIUM6.5When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location....
CVE-2020-6792MEDIUM4.3When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. Thi...
CVE-2020-6804MEDIUM6.1A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could ste...
CVE-2020-6803MEDIUM6.1An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site a...
CVE-2020-9459MEDIUM5.4Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1....
CVE-2020-9466MEDIUM6.1The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection.
CVE-2020-8127MEDIUM6.1Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attacke...
CVE-2020-1877MEDIUM4.4NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid poi...
CVE-2020-1875MEDIUM5.5NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid...
CVE-2020-1874MEDIUM5.5NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have a invalid ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now