2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-15386MEDIUM5.3Brocade Fabric OS prior to v9.0.1a and 8.2.3a and after v9.0.0 and 8.2.2d may observe high CPU load during security scan...
CVE-2020-15385MEDIUM5.4Brocade SANnav before version 2.1.1 allows an authenticated attacker to list directories, and list files without permiss...
CVE-2020-15384MEDIUM5.3Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of interna...
CVE-2020-15378MEDIUM5.3The OVA version of Brocade SANnav before version 2.1.1 installation with IPv6 networking exposes the docker container po...
CVE-2020-11266MEDIUM6.5Image address is dereferenced before validating its range which can cause potential QSEE information leakage in Snapdrag...
CVE-2020-11265MEDIUM5.5Information disclosure issue due to lack of validation of pointer arguments passed to TZ BSP in Snapdragon Wired Infrast...
CVE-2020-11160MEDIUM6.7Resource leakage issue during dci client registration due to reference count is not decremented if dci client registrati...
CVE-2020-26136MEDIUM6.5In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authenticat...
CVE-2020-28713MEDIUM6.5Incorrect access control in push notification service in Night Owl Smart Doorbell FW version 20190505 allows remote user...
CVE-2020-26138MEDIUM5.3In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation.
CVE-2020-25817MEDIUM4.8SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML ...
CVE-2020-26517MEDIUM4.8A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to per...
CVE-2020-1750MEDIUM6.5A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container co...
CVE-2020-1690MEDIUM6.5An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root...
CVE-2020-18268MEDIUM6.1Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect"...
CVE-2020-1719MEDIUM5.4A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Se...
CVE-2020-5008MEDIUM5.3IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET r...
CVE-2020-36384MEDIUM6.1PageLayer before 1.3.5 allows reflected XSS via color settings.
CVE-2020-36383MEDIUM6.1PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.
CVE-2020-26885MEDIUM6.1An issue was discovered in 2sic 2sxc before 11.22. A XSS vulnerability in the sxcver parameter of dnn/ui.html allows an ...
CVE-2020-36142MEDIUM6.5BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
CVE-2020-36140MEDIUM6.5BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of '...
CVE-2020-36139MEDIUM5.4BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'file...
CVE-2020-15077MEDIUM5.3OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control c...
CVE-2020-36007MEDIUM6.1AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now