2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-19288MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to exec...
CVE-2020-19287MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execu...
CVE-2020-19286MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to ...
CVE-2020-19285MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to exec...
CVE-2020-19284MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to ex...
CVE-2020-19283MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to ex...
CVE-2020-19282MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts o...
CVE-2020-19281MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attacker...
CVE-2020-19268MEDIUM5.7A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to a...
CVE-2020-19266MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Site/articleList component of Dswjcms 1.6.4 a...
CVE-2020-19265MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Basis/links component of Dswjcms 1.6.4 allows...
CVE-2020-19264MEDIUM6.5A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily add users via index.php?s=/user/Api...
CVE-2020-19515MEDIUM6.1qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
CVE-2020-19144MEDIUM6.5Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the...
CVE-2020-19143MEDIUM6.5Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the ...
CVE-2020-27940MEDIUM4.3This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0....
CVE-2020-29012MEDIUM5.3An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse...
CVE-2020-19855MEDIUM6.1phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.
CVE-2020-15939MEDIUM4.3An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allo...
CVE-2020-20349MEDIUM5.4WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background link...
CVE-2020-20348MEDIUM5.4WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu managem...
CVE-2020-20347MEDIUM5.4WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management mo...
CVE-2020-20345MEDIUM5.4WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows ...
CVE-2020-20344MEDIUM5.4WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the backgr...
CVE-2020-20343MEDIUM6.5WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now