2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-23190 | MEDIUM | 5.4 | 0.5% | Jul 2, 2021 | A stored cross site scripting (XSS) vulnerability in the "Import emails" module in phplist 3.5.4 allows authenticated at... |
| CVE-2020-23185 | MEDIUM | 5.4 | 0.4% | Jul 2, 2021 | A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows a... |
| CVE-2020-23184 | MEDIUM | 5.4 | 0.4% | Jul 2, 2021 | A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 all... |
| CVE-2020-23182 | MEDIUM | 5.4 | 0.5% | Jul 2, 2021 | The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redire... |
| CVE-2020-23181 | MEDIUM | 5.4 | 0.4% | Jul 2, 2021 | A reflected cross site scripting (XSS) vulnerability in /administration/theme.php of PHP-Fusion 9.03.60 allows authentic... |
| CVE-2020-23179 | MEDIUM | 5.4 | 0.5% | Jul 2, 2021 | A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authe... |
| CVE-2020-23178 | MEDIUM | 5.4 | 0.5% | Jul 2, 2021 | An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attack... |
| CVE-2020-23217 | MEDIUM | 5.4 | 0.6% | Jul 1, 2021 | A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or ... |
| CVE-2020-23214 | MEDIUM | 5.4 | 0.6% | Jul 1, 2021 | A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or ... |
| CVE-2020-23209 | MEDIUM | 5.4 | 0.5% | Jul 1, 2021 | A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or ... |
| CVE-2020-23208 | MEDIUM | 5.4 | 0.6% | Jul 1, 2021 | A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or ... |
| CVE-2020-23207 | MEDIUM | 5.4 | 0.5% | Jul 1, 2021 | A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or ... |
| CVE-2020-23205 | MEDIUM | 5.4 | 0.5% | Jul 1, 2021 | A stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web... |
| CVE-2020-4935 | MEDIUM | 5.4 | 0.5% | Jul 1, 2021 | IBM Datacap Fastdoc Capture (IBM Datacap Navigator 9.1.7 ) is vulnerable to cross-site scripting. This vulnerability all... |
| CVE-2020-36196 | MEDIUM | 6.1 | 0.6% | Jul 1, 2021 | A stored XSS vulnerability has been reported to affect QNAP NAS running QuLog Center. If exploited, this vulnerability a... |
| CVE-2020-36194 | MEDIUM | 6.1 | 0.6% | Jul 1, 2021 | An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability al... |
| CVE-2020-18066 | MEDIUM | 6.1 | 0.6% | Jun 29, 2021 | Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment. |
| CVE-2020-21142 | MEDIUM | 6.1 | 0.7% | Jun 28, 2021 | Cross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi. |
| CVE-2020-22609 | MEDIUM | 6.1 | 0.7% | Jun 28, 2021 | Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/... |
| CVE-2020-22608 | MEDIUM | 6.1 | 0.7% | Jun 28, 2021 | Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.s... |
| CVE-2020-22607 | MEDIUM | 6.1 | 0.7% | Jun 28, 2021 | Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in applica... |
| CVE-2020-20640 | MEDIUM | 6.1 | 1.0% | Jun 28, 2021 | Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can us... |
| CVE-2020-23710 | MEDIUM | 5.4 | 0.6% | Jun 28, 2021 | Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature. |
| CVE-2020-28200 | MEDIUM | 4.3 | 2.0% | Jun 28, 2021 | The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with ... |
| CVE-2020-15303 | MEDIUM | 6.5 | 0.9% | Jun 28, 2021 | Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now