2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-9338MEDIUM5.4SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.
CVE-2020-9336MEDIUM5.4fauzantrif eLection 2.0 has XSS via the Admin Dashboard -> Settings -> Election -> "message if election is closed" field...
CVE-2020-9329MEDIUM5.9Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go ...
CVE-2020-5326MEDIUM5.3Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot In...
CVE-2020-5324MEDIUM4.4Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is li...
CVE-2020-5533MEDIUM6.1Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.3.2 and earlier allows remote attackers to inject arb...
CVE-2020-8960MEDIUM6.1Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS.
CVE-2020-9320MEDIUM5.5Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before ...
CVE-2020-9003MEDIUM5.4A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation...
CVE-2020-6977MEDIUM6.8A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specia...
CVE-2020-7942MEDIUM6.5Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the syste...
CVE-2020-3163MEDIUM5.9A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an unauthenticated, remot...
CVE-2020-3160MEDIUM5.3A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could ...
CVE-2020-3159MEDIUM6.1A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t...
CVE-2020-3156MEDIUM6.1A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated remote attacke...
CVE-2020-3154MEDIUM4.9A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute...
CVE-2020-3153MEDIUM6.5A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authent...
CVE-2020-3138MEDIUM6.7A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenti...
CVE-2020-3132MEDIUM5.9A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)...
CVE-2020-3113MEDIUM5.4A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authent...
CVE-2020-8824MEDIUM5.4Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed Device name on the Wireless > Access Control > Add Managed De...
CVE-2020-4230MEDIUM6.7IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privil...
CVE-2020-4200MEDIUM6.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated atta...
CVE-2020-4161MEDIUM6.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 could allow an authenticated attacker to cause a ...
CVE-2020-8633MEDIUM5.3An issue was discovered in Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7. When grantors revoked a shared calend...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now