2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-7052MEDIUM6.5CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a r...
CVE-2020-7937MEDIUM5.4An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScr...
CVE-2020-7936MEDIUM6.1An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a ...
CVE-2020-6843MEDIUM4.8Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-839...
CVE-2020-7210MEDIUM4.3Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
CVE-2020-5217MEDIUM5.8In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1...
CVE-2020-5216MEDIUM5.8In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2...
CVE-2020-5223MEDIUM4.4In PrivateBin versions 1.2.0 before 1.2.2, and 1.3.0 before 1.3.2, a persistent XSS attack is possible. Under certain co...
CVE-2020-7915MEDIUM4.8An issue was discovered on Eaton 5P 850 devices. The Ubicacion SAI field allows XSS attacks by an administrator.
CVE-2020-7228MEDIUM5.4The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present...
CVE-2020-1788MEDIUM5.5Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. ...
CVE-2020-1840MEDIUM6HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulner...
CVE-2020-5202MEDIUM5.5apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /u...
CVE-2020-6857MEDIUM5.5CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FT...
CVE-2020-7470MEDIUM4.8Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login wi...
CVE-2020-7239MEDIUM6.1The conversation-watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a cha...
CVE-2020-7249MEDIUM4.8SMC D3G0804W 3.5.2.5-LAT_GA devices allow XSS via the SSID field on the WiFi Network Configuration page (after a success...
CVE-2020-7215MEDIUM5.5An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 befor...
CVE-2020-7236MEDIUM6.1UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cw2?td= (Site Name field of the Site Setup section).
CVE-2020-7235MEDIUM6.1UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cB3?ta= (profile title).
CVE-2020-7234MEDIUM4.8Ruckus ZoneFlex R310 104.0.0.0.1347 devices allow Stored XSS via the SSID field on the Configuration > Radio 2.4G > Wire...
CVE-2020-7231MEDIUM5.3Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is ...
CVE-2020-7227MEDIUM6.5Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remot...
CVE-2020-7222MEDIUM5.3An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with ...
CVE-2020-7104MEDIUM6.1The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions paramete...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now