2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-20472MEDIUM5.3White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does no...
CVE-2020-20470MEDIUM5.3White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability.
CVE-2020-20468MEDIUM6.5White Shark System (WSS) 1.3.2 is vulnerable to CSRF. Attackers can use the user_edit_password.php file to modify the us...
CVE-2020-20467MEDIUM6.5White Shark System (WSS) 1.3.2 is vulnerable to sensitive information disclosure via default_task_add.php, remote attack...
CVE-2020-36389MEDIUM4.3In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF.
CVE-2020-35373MEDIUM6.1In Fiyo CMS 2.0.6.1, the 'tag' parameter results in an unauthenticated XSS attack.
CVE-2020-19202MEDIUM5.4An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Pa...
CVE-2020-25752MEDIUM5.3An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the in...
CVE-2020-22200MEDIUM5.3Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.
CVE-2020-35761MEDIUM5.4bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.
CVE-2020-35759MEDIUM6.5bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).
CVE-2020-27339MEDIUM6.7In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize ...
CVE-2020-8300MEDIUM6.5Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-5...
CVE-2020-8299MEDIUM6.5Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1...
CVE-2020-5000MEDIUM5.4IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows u...
CVE-2020-29215MEDIUM5.4A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /E...
CVE-2020-21316MEDIUM6.1A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers t...
CVE-2020-12987MEDIUM5.5A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead ...
CVE-2020-13688MEDIUM6.1Cross-site scripting vulnerability in l Drupal Core allows an attacker could leverage the way that HTML is rendered for ...
CVE-2020-25467MEDIUM5.5A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to caus...
CVE-2020-24668MEDIUM5.4Trace Financial Crest Bridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03.
CVE-2020-24663MEDIUM5.4Trace Financial CRESTBridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03.
CVE-2020-24662MEDIUM5.4SmartStream Transaction Lifecycle Management (TLM) Reconciliation Premium (RP) <3.1.0 allows XSS. This was fixed in TLM ...
CVE-2020-13938MEDIUM5.5Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
CVE-2020-24475MEDIUM5.5Improper initialization in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before v...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now