2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-7997MEDIUM6.1ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature.
CVE-2020-1933MEDIUM6.1A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through acti...
CVE-2020-1932MEDIUM6.5An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Su...
CVE-2020-1928MEDIUM5.3An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed...
CVE-2020-0549MEDIUM5.5Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially ...
CVE-2020-0548MEDIUM5.5Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure ...
CVE-2020-8091MEDIUM6.1svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cr...
CVE-2020-8090MEDIUM4.8The Username field in the Storage Service settings of A1 WLAN Box ADB VV2220v2 devices allows stored XSS (after a succes...
CVE-2020-5220MEDIUM5.3Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data ...
CVE-2020-5218MEDIUM4.3Affected versions of Sylius give attackers the ability to switch channels via the _channel_code GET parameter in product...
CVE-2020-8003MEDIUM5.5A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of ser...
CVE-2020-8002MEDIUM5.5A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of serv...
CVE-2020-7996MEDIUM6.1htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.
CVE-2020-7994MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web sc...
CVE-2020-7990MEDIUM6.1Adive Framework 2.0.8 has admin/user/add userName XSS.
CVE-2020-7989MEDIUM6.1Adive Framework 2.0.8 has admin/user/add userUsername XSS.
CVE-2020-3139MEDIUM5.3A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Inf...
CVE-2020-3136MEDIUM6.1A vulnerability in the web-based management interface of Cisco Jabber Guest could allow an unauthenticated, remote attac...
CVE-2020-3134MEDIUM6.5A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could...
CVE-2020-3131MEDIUM6.5A vulnerability in the Cisco Webex Teams client for Windows could allow an authenticated, remote attacker to cause the c...
CVE-2020-3129MEDIUM4.8A vulnerability in the web-based management interface of Cisco Unity Connection Software could allow an authenticated, r...
CVE-2020-3121MEDIUM6.1A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an ...
CVE-2020-5226MEDIUM5.4Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be su...
CVE-2020-5225MEDIUM5.4Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and se...
CVE-2020-7964MEDIUM5.3An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutat...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now