2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-24826MEDIUM5.5A vulnerability in the elf::section::as_strtab function of Libelfin v0.3 allows attackers to cause a denial of service (...
CVE-2020-24825MEDIUM5.5A vulnerability in the line_table::line_table function of Libelfin v0.3 allows attackers to cause a denial of service (D...
CVE-2020-24824MEDIUM5.5A global buffer overflow issue in the dwarf::line_table::line_table function of Libelfin v0.3 allows attackers to cause ...
CVE-2020-24823MEDIUM5.5A vulnerability in the dwarf::to_string function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) th...
CVE-2020-24822MEDIUM5.5A vulnerability in the dwarf::cursor::uleb function of Libelfin v0.3 allows attackers to cause a denial of service (DOS)...
CVE-2020-24821MEDIUM5.5A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service ...
CVE-2020-4707MEDIUM5.4IBM API Connect 5.0.0.0 through 5.0.8.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2020-26564MEDIUM6.5ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create ...
CVE-2020-26563MEDIUM6.1ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query st...
CVE-2020-22765MEDIUM6.1Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.
CVE-2020-21854MEDIUM6.1Cross Site Scripting vulnerabiity exists in WDScanner 1.1 in the system management page.
CVE-2020-20701MEDIUM4.8A stored cross site scripting (XSS) vulnerability in /app/config/of S-CMS PHP v3.0 allows attackers to execute arbitrary...
CVE-2020-20700MEDIUM4.8A stored cross site scripting (XSS) vulnerability in /app/form_add/of S-CMS PHP v3.0 allows attackers to execute arbitra...
CVE-2020-20699MEDIUM4.8A cross site scripting (XSS) vulnerability in S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML v...
CVE-2020-19118MEDIUM5.4Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.
CVE-2020-18158MEDIUM5.4Cross Site Scripting (XSS) vulnerability in HuCart 5.7.4 via nickname in index.php.
CVE-2020-15948MEDIUM6.1eGain Chat 15.5.5 allows XSS via the Name (aka full_name) field.
CVE-2020-5329MEDIUM6.1Dell EMC Avamar Server contains an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulne...
CVE-2020-5004MEDIUM5.4IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2020-4974MEDIUM6.3IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attac...
CVE-2020-23243MEDIUM4.8Cross Site Scripting (XSS) vulnerability in NavigateCMS NavigateCMS 2.9 via the name="wrong_path_redirect" feature.
CVE-2020-23242MEDIUM4.8Cross Site Scripting (XSS) vulnerability in NavigateCMS 2.9 when performing a Create or Edit via the Tools feature.
CVE-2020-23241MEDIUM4.8Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.14 in "Extra" via 'News > Article" feature.
CVE-2020-23240MEDIUM4.8Cross Site Scripting (XSS) vulnerablity in CMS Made Simple 2.2.14 via the Logic field in the Content Manager feature.
CVE-2020-23239MEDIUM4.8Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now