2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-28911MEDIUM6.5Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwor...
CVE-2020-28903MEDIUM6.1Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server t...
CVE-2020-26006MEDIUM6.1Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php.
CVE-2020-25411MEDIUM6.5Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing...
CVE-2020-25408MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows ...
CVE-2020-23766MEDIUM6.5An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolut...
CVE-2020-27211MEDIUM5.7Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The fl...
CVE-2020-27208MEDIUM6.8The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4....
CVE-2020-21345MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a rem...
CVE-2020-21056MEDIUM4.3Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via ...
CVE-2020-21055MEDIUM6.5A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.vi...
CVE-2020-21054MEDIUM6.1Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script...
CVE-2020-21053MEDIUM6.1Cross Site Scriptiong (XSS) vulnerability exists in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary we...
CVE-2020-24395MEDIUM6.8The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical acces...
CVE-2020-15522MEDIUM5.9Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 ha...
CVE-2020-4646MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5, 6.0.0.0 through 6.0.3.3, and 6.1.0.0 through 6.1.0...
CVE-2020-36365MEDIUM6.1Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, ...
CVE-2020-20266MEDIUM6.5Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/dot1x proces...
CVE-2020-20264MEDIUM6.5Mikrotik RouterOs before 6.47 (stable tree) in the /ram/pckg/advanced-tools/nova/bin/netwatch process. An authenticated ...
CVE-2020-20246MEDIUM6.5Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the mactel process. An authenticated r...
CVE-2020-20245MEDIUM6.5Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the log process. An authenticated remo...
CVE-2020-20227MEDIUM6.5Mikrotik RouterOs stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenti...
CVE-2020-20220MEDIUM6.5Mikrotik RouterOs prior to stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/bfd process. An a...
CVE-2020-19924MEDIUM5.4In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks.
CVE-2020-20237MEDIUM6.5Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now