2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-20265MEDIUM6.5Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /ram/pckg/wireless/nov...
CVE-2020-35438MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the kk Star Ratings plugin before 4.1.5.
CVE-2020-23376MEDIUM6.1NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation col...
CVE-2020-23374MEDIUM5.4Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attacke...
CVE-2020-23373MEDIUM5.4Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers t...
CVE-2020-23371MEDIUM6.1Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCm...
CVE-2020-23370MEDIUM5.4In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which...
CVE-2020-23369MEDIUM6.1In YzmCMS 5.6, XSS was discovered in member/member_content/init.html via the SRC attribute of an IFRAME element because ...
CVE-2020-18102MEDIUM6.1Cross Site Scripting (XSS) in Hotels_Server v1.0 allows remote attackers to execute arbitrary code by injecting crafted ...
CVE-2020-28588MEDIUM5.5An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4...
CVE-2020-13529MEDIUM6.1An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cau...
CVE-2020-4901MEDIUM6.5IBM Robotic Process Automation with Automation Anywhere 11.0 could allow an attacker on the network to obtain sensitive ...
CVE-2020-14009MEDIUM6.3Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to delive...
CVE-2020-36127MEDIUM6.5Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by an information disclosure vulnerability. Through ...
CVE-2020-36124MEDIUM6.5Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authentic...
CVE-2020-11293MEDIUM6Out of bound read can happen in Widevine TA while copying data to buffer from user data due to lack of check of buffer l...
CVE-2020-11254MEDIUM5.5Memory corruption during buffer allocation due to dereferencing session ctx pointer without checking if pointer is valid...
CVE-2020-29445MEDIUM4.3Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify i...
CVE-2020-29444MEDIUM5.4Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javasc...
CVE-2020-23263MEDIUM6.1Persistent Cross-site scripting vulnerability on Fork CMS version 5.8.2 allows remote attackers to inject arbitrary Java...
CVE-2020-18889MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/setting...
CVE-2020-28014MEDIUM6.1Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and all...
CVE-2020-23128MEDIUM4.9Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege t...
CVE-2020-4993MEDIUM4.9IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be v...
CVE-2020-4929MEDIUM5.4IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now