2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-20472 | MEDIUM | 5.3 | 1.5% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does no... |
| CVE-2020-20470 | MEDIUM | 5.3 | 0.9% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability. |
| CVE-2020-20468 | MEDIUM | 6.5 | 0.5% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 is vulnerable to CSRF. Attackers can use the user_edit_password.php file to modify the us... |
| CVE-2020-20467 | MEDIUM | 6.5 | 1.2% | Jun 21, 2021 | White Shark System (WSS) 1.3.2 is vulnerable to sensitive information disclosure via default_task_add.php, remote attack... |
| CVE-2020-36389 | MEDIUM | 4.3 | 0.7% | Jun 17, 2021 | In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF. |
| CVE-2020-35373 | MEDIUM | 6.1 | 0.7% | Jun 17, 2021 | In Fiyo CMS 2.0.6.1, the 'tag' parameter results in an unauthenticated XSS attack. |
| CVE-2020-19202 | MEDIUM | 5.4 | 0.6% | Jun 17, 2021 | An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Pa... |
| CVE-2020-25752 | MEDIUM | 5.3 | 1.6% | Jun 16, 2021 | An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the in... |
| CVE-2020-22200 | MEDIUM | 5.3 | 1.4% | Jun 16, 2021 | Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword. |
| CVE-2020-35761 | MEDIUM | 5.4 | 0.8% | Jun 16, 2021 | bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code. |
| CVE-2020-35759 | MEDIUM | 6.5 | 0.8% | Jun 16, 2021 | bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely). |
| CVE-2020-27339 | MEDIUM | 6.7 | 0.3% | Jun 16, 2021 | In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize ... |
| CVE-2020-8300 | MEDIUM | 6.5 | 3.0% | Jun 16, 2021 | Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-5... |
| CVE-2020-8299 | MEDIUM | 6.5 | 0.4% | Jun 16, 2021 | Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1... |
| CVE-2020-5000 | MEDIUM | 5.4 | 0.5% | Jun 15, 2021 | IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows u... |
| CVE-2020-29215 | MEDIUM | 5.4 | 0.6% | Jun 15, 2021 | A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /E... |
| CVE-2020-21316 | MEDIUM | 6.1 | 1.1% | Jun 15, 2021 | A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers t... |
| CVE-2020-12987 | MEDIUM | 5.5 | 0.3% | Jun 11, 2021 | A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead ... |
| CVE-2020-13688 | MEDIUM | 6.1 | 0.7% | Jun 11, 2021 | Cross-site scripting vulnerability in l Drupal Core allows an attacker could leverage the way that HTML is rendered for ... |
| CVE-2020-25467 | MEDIUM | 5.5 | 0.9% | Jun 10, 2021 | A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to caus... |
| CVE-2020-24668 | MEDIUM | 5.4 | 0.5% | Jun 10, 2021 | Trace Financial Crest Bridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03. |
| CVE-2020-24663 | MEDIUM | 5.4 | 0.5% | Jun 10, 2021 | Trace Financial CRESTBridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03. |
| CVE-2020-24662 | MEDIUM | 5.4 | 0.5% | Jun 10, 2021 | SmartStream Transaction Lifecycle Management (TLM) Reconciliation Premium (RP) <3.1.0 allows XSS. This was fixed in TLM ... |
| CVE-2020-13938 | MEDIUM | 5.5 | 11.8% | Jun 10, 2021 | Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows |
| CVE-2020-24475 | MEDIUM | 5.5 | 0.2% | Jun 9, 2021 | Improper initialization in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before v... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now