2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-3169MEDIUM6.7A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary comm...
CVE-2020-3166MEDIUM6.7A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrar...
CVE-2020-8952MEDIUM6.1Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the logout.jsp timeOut parameter.
CVE-2020-8951MEDIUM5.4Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the Source or Destination field of the C...
CVE-2020-9337MEDIUM6.5In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.
CVE-2020-9407MEDIUM5.3IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COO...
CVE-2020-9405MEDIUM6.1IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.
CVE-2020-9393MEDIUM6.1An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.
CVE-2020-9379MEDIUM6.5The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB4962...
CVE-2020-9391MEDIUM5.5An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top by...
CVE-2020-9019MEDIUM6.1The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Descr...
CVE-2020-9018MEDIUM5.3LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.
CVE-2020-9008MEDIUM5.4Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web...
CVE-2020-9335MEDIUM4.8Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploita...
CVE-2020-9334MEDIUM5.4A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitatio...
CVE-2020-8793MEDIUM4.7OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combi...
CVE-2020-9382MEDIUM5.4An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for th...
CVE-2020-1935MEDIUM4.8In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach t...
CVE-2020-8130MEDIUM6.4There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that be...
CVE-2020-5188MEDIUM6.5DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
CVE-2020-5186MEDIUM5.4DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
CVE-2020-9351MEDIUM5.3An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerCons...
CVE-2020-9350MEDIUM5.4Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.
CVE-2020-9342MEDIUM5.5The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a ...
CVE-2020-9339MEDIUM5.4SOPlanning 1.45 allows XSS via the Name or Comment to status.php.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now