2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-8117MEDIUM4.3Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non...
CVE-2020-8115MEDIUM6.1A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver ...
CVE-2020-3939MEDIUM6.1SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Cross-Site Scripting(XSS), personal informa...
CVE-2020-5236MEDIUM6.5Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid characters. When a head...
CVE-2020-8549MEDIUM6.1Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious ...
CVE-2020-8548MEDIUM6.1massCode 1.0.0-alpha.6 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegrati...
CVE-2020-5182MEDIUM6.5The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link t...
CVE-2020-4224MEDIUM5.5IBM StoredIQ 7.6.0.17 through 7.6.0.20 could disclose sensitive information to a local user due to data in certain direc...
CVE-2020-7993MEDIUM4.3Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a mo...
CVE-2020-8514MEDIUM6.1An issue was discovered in Rumpus 8.2.10 on macOS. By crafting a directory name, it is possible to activate JavaScript i...
CVE-2020-8516MEDIUM5.3The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before att...
CVE-2020-8512MEDIUM6.1In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.
CVE-2020-8505MEDIUM6.5School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.
CVE-2020-8504MEDIUM6.5School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrati...
CVE-2020-8503MEDIUM6.5Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object ...
CVE-2020-5234MEDIUM6.5MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS a...
CVE-2020-8422MEDIUM4.3An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 1...
CVE-2020-7955MEDIUM5.3HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resu...
CVE-2020-5526MEDIUM5.9The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from server...
CVE-2020-8498MEDIUM5.4XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gist...
CVE-2020-8496MEDIUM4.8In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability b...
CVE-2020-8493MEDIUM4.8A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via...
CVE-2020-5231MEDIUM6.5In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new user...
CVE-2020-8095MEDIUM5.5A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an at...
CVE-2020-8492MEDIUM6.5Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTT...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now