2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-6173MEDIUM5.3TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.
CVE-2020-6307MEDIUM4.3Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) doe...
CVE-2020-6305MEDIUM6.1PI Rest Adapter of SAP Process Integration (update provided in SAP_XIAF 7.31, 7.40, 7.50) does not sufficiently encode u...
CVE-2020-6303MEDIUM5.4SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to C...
CVE-2020-5193MEDIUM6.1PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata...
CVE-2020-5853MEDIUM5.4In BIG-IP APM portal access on versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6....
CVE-2020-5851MEDIUM4.6On impacted versions and platforms the Trusted Platform Module (TPM) system integrity check cannot detect modifications ...
CVE-2020-5194MEDIUM5.4The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip fun...
CVE-2020-6955MEDIUM6.1An issue was discovered on Cayin SMP-PRO4 devices. They allow image_preview.html?filename= reflected XSS.
CVE-2020-6954MEDIUM6.5An issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Conne...
CVE-2020-6832MEDIUM5.3An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was...
CVE-2020-5197MEDIUM4.3An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrec...
CVE-2020-5195MEDIUM6.1Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remote attacke...
CVE-2020-6859MEDIUM5.3Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin...
CVE-2020-6848MEDIUM6.1Axper Vision II 4 devices allow XSS via the DEVICE_NAME (aka Device Name) parameter to the configWebParams.cgi URI.
CVE-2020-6847MEDIUM5.4OpenTrade through 0.2.0 has a DOM-based XSS vulnerability that is executed when an administrator attempts to delete a me...
CVE-2020-1767MEDIUM4.3Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely a...
CVE-2020-1766MEDIUM6.1Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents brow...
CVE-2020-1765MEDIUM5.3An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, A...
CVE-2020-6758MEDIUM6.1A cross-site scripting (XSS) vulnerability in Option/optionsAll.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI...
CVE-2020-6750MEDIUM5.9GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting v...
CVE-2020-6166MEDIUM5.4A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with bas...
CVE-2020-1810MEDIUM5.3There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA algorithm in the SSL ...
CVE-2020-1786MEDIUM4.6HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerabilit...
CVE-2020-1826MEDIUM4.4Huawei Honor Magic2 mobile phones with versions earlier than 10.0.0.175(C00E59R2P11) have an information leak vulnerabil...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now