2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-9028MEDIUM6.1Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via t...
CVE-2020-9025MEDIUM6.1Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Vie...
CVE-2020-9022MEDIUM6.1An issue was discovered on Xirrus XR520, XR620, XR2436, and XH2-120 devices. The cgi-bin/ViewPage.cgi user parameter all...
CVE-2020-9016MEDIUM5.4Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.
CVE-2020-9013MEDIUM4.3Arvato Skillpipe 3.0 allows attackers to bypass intended print restrictions by deleting <div id="watermark"> from the HT...
CVE-2020-9012MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows ...
CVE-2020-9007MEDIUM5.4Codoforum 4.8.8 allows self-XSS via the title of a new topic.
CVE-2020-8996MEDIUM4.3AnyShare Cloud 6.0.9 allows authenticated directory traversal to read files, as demonstrated by the interface/downloadwi...
CVE-2020-7050MEDIUM5.4Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to...
CVE-2020-8594MEDIUM5.4The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key],...
CVE-2020-7251MEDIUM5.5Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 Feb...
CVE-2020-5532MEDIUM4.3ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker o...
CVE-2020-8992MEDIUM5.5ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a de...
CVE-2020-8989MEDIUM5.3In the Voatz application 2020-01-01 for Android, the amount of data transmitted during a single voter's vote depends on ...
CVE-2020-8988MEDIUM5.9The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers...
CVE-2020-8981MEDIUM6.1A cross-site scripting (XSS) vulnerability was discovered in the Source Integration plugin before 1.6.2 and 2.x before 2...
CVE-2020-8804MEDIUM6.5SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.
CVE-2020-7051MEDIUM6.1Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-584...
CVE-2020-0028MEDIUM6.5In notifyNetworkTested and related functions of NetworkMonitor.java, there is a possible bypass of private DNS settings....
CVE-2020-0023MEDIUM5.5In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth d...
CVE-2020-0021MEDIUM6.5In removeUnusedPackagesLPw of PackageManagerService.java, there is a possible permanent denial-of-service due to a missi...
CVE-2020-0020MEDIUM5.5In getAttributeRange of ExifInterface.java, there is a possible failure to redact location information from media files ...
CVE-2020-0018MEDIUM4.4In MotionEntry::appendDescription of InputDispatcher.cpp, there is a possible log information disclosure. This could lea...
CVE-2020-0017MEDIUM4.4In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users...
CVE-2020-0014MEDIUM5.5It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. Thi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now