2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-36861MEDIUM5.4The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.8 / Nagios XI 5.7.5 contains multiple cross-site sc...
CVE-2020-36860MEDIUM5.4The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple cross-site sc...
CVE-2020-36858MEDIUM5.4Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on th...
CVE-2020-36855MEDIUM5.5A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the ...
CVE-2020-36854MEDIUM6.4The Async JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,...
CVE-2020-36790MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a memory leak We forgot to free new_mod...
CVE-2020-36845MEDIUM6.1The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validat...
CVE-2020-36844MEDIUM6.1The KnowBe4 Security Awareness Training application before 2020-01-10 allows reflected XSS. The response has a SCRIPT el...
CVE-2020-36789MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree...
CVE-2020-18243MEDIUM6.5SQL injection vulnerability found in Enricozab CMS v.1.0 allows a remote attacker to execute arbitrary code via /hdo/hdo...
CVE-2020-29010MEDIUM5An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version ...
CVE-2020-36843MEDIUM4.3The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not ...
CVE-2020-3122MEDIUM5.3A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (...
CVE-2020-19248MEDIUM5.1SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's abi...
CVE-2020-6158MEDIUM4.7Opera Mini for Android before version 52.2 is vulnerable to an address bar spoofing attack. The vulnerability allows a m...
CVE-2020-13481MEDIUM6.1Certain Lexmark products through 2020-05-25 allow XSS which allows an attacker to obtain session credentials and other s...
CVE-2020-3432MEDIUM5.6A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authen...
CVE-2020-36085MEDIUM6.3Stored Cross Site Scripting(XSS) vulnerability in Egavilan Media Resumes Management and Job Application Website 1.0 allo...
CVE-2020-1824MEDIUM5.3There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP...
CVE-2020-1823MEDIUM5.3There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP...
CVE-2020-1822MEDIUM5.3There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP...
CVE-2020-1821MEDIUM5.3There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP...
CVE-2020-1820MEDIUM5.3There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COP...
CVE-2020-9253MEDIUM6.5There is a stack overflow vulnerability in some Huawei smart phone. An attacker can craft specific packet to exploit thi...
CVE-2020-9210MEDIUM6.8There is an insufficient integrity vulnerability in Huawei products. A module does not perform sufficient integrity chec...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now