2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-6399MEDIUM6.5Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cro...
CVE-2020-6397MEDIUM6.5Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof securi...
CVE-2020-6396MEDIUM4.3Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the conte...
CVE-2020-6395MEDIUM6.5Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially ...
CVE-2020-6394MEDIUM5.4Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass cont...
CVE-2020-6393MEDIUM6.5Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-...
CVE-2020-6392MEDIUM4.3Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a...
CVE-2020-6391MEDIUM4.3Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to b...
CVE-2020-3933MEDIUM5.3TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, allows attackers to enumerate ...
CVE-2020-8089MEDIUM5.4Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page.
CVE-2020-1697MEDIUM5.4It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin ...
CVE-2020-8825MEDIUM5.4index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
CVE-2020-8823MEDIUM6.1htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka cal...
CVE-2020-8822MEDIUM4.8Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices allow stored XSS in the web application.
CVE-2020-8812MEDIUM5.4Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's per...
CVE-2020-8811MEDIUM4.3ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.
CVE-2020-1700MEDIUM6.5A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can a...
CVE-2020-1768MEDIUM5.4The external frontend system uses numerous background calls to the backend. Each background request is treated as user a...
CVE-2020-8788MEDIUM6.1Synaptive Medical ClearCanvas ImageServer 3.0 Alpha allows XSS (and HTML injection) via the Default.aspx UserName parame...
CVE-2020-5317MEDIUM4.8Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user could exploit...
CVE-2020-8608MEDIUM5.6In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in lat...
CVE-2020-6856MEDIUM6.5An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allow...
CVE-2020-6855MEDIUM6.5A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers...
CVE-2020-6767MEDIUM6.5A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated r...
CVE-2020-5720MEDIUM5.9MikroTik WinBox before 3.21 is vulnerable to a path traversal vulnerability that allows creation of arbitrary files wher...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now