2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25088MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.
CVE-2020-25087MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/langua...
CVE-2020-25086MEDIUM6.1Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminU...
CVE-2020-5420HIGH7.7Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with "cf push" access to cause de...
CVE-2020-5418MEDIUM4.3Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controll...
CVE-2020-5386HIGH7.5Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker c...
CVE-2020-5379MEDIUM6.8Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacke...
CVE-2020-5378MEDIUM6.8Dell G7 17 7790 BIOS versions prior to 1.13.2 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacke...
CVE-2020-5376MEDIUM6.8Dell Inspiron 7347 BIOS versions prior to A13 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacke...
CVE-2020-5369HIGH8.8Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalat...
CVE-2020-8576MEDIUM5.4Clustered Data ONTAP versions prior to 9.3P19, 9.5P14, 9.6P9 and 9.7 are susceptible to a vulnerability which when succe...
CVE-2020-7830HIGH7.8RAONWIZ v2018.0.2.50 and earlier versions contains a vulnerability that could allow remote files to be downloaded by lac...
CVE-2020-5779HIGH7.5A flaw in Trading Technologies Messaging 7.1.28.3 (ttmd.exe) relates to invalid parameter handling when calling strcpy_s...
CVE-2020-5778HIGH7.5A flaw exists in Trading Technologies Messaging 7.1.28.3 (ttmd.exe) due to improper validation of user-supplied data whe...
CVE-2020-25045HIGH7.8Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were...
CVE-2020-25044HIGH7.1Kaspersky Virus Removal Tool (KVRT) prior to 15.0.23.0 was vulnerable to arbitrary file corruption that could provide an...
CVE-2020-25043HIGH7.1The installer of Kaspersky VPN Secure Connection prior to 5.0 was vulnerable to arbitrary file deletion that could allow...
CVE-2020-4693CRITICAL9.8IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to exe...
CVE-2020-4546MEDIUM5.4IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2020-4522MEDIUM5.4IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2020-4445MEDIUM5.4IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2020-15167HIGH8.6In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an...
CVE-2020-15094HIGH8.8In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on...
CVE-2020-25026MEDIUM4.3The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows In...
CVE-2020-25025MEDIUM4.3The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows I...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now