2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4883 | MEDIUM | 6.5 | 0.8% | May 5, 2021 | IBM QRadar SIEM 7.3 and 7.4 could disclose sensitive information about other domains which could be used in further atta... |
| CVE-2020-13662 | MEDIUM | 6.1 | 0.9% | May 5, 2021 | Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which woul... |
| CVE-2020-13666 | MEDIUM | 6.1 | 2.9% | May 5, 2021 | Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XS... |
| CVE-2020-22428 | MEDIUM | 4.8 | 1.2% | May 5, 2021 | SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an a... |
| CVE-2020-4987 | MEDIUM | 5.4 | 0.5% | May 4, 2021 | The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and pr... |
| CVE-2020-23015 | MEDIUM | 6.1 | 2.7% | May 3, 2021 | An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not fil... |
| CVE-2020-28945 | MEDIUM | 6.1 | 1.1% | May 3, 2021 | OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as  suffers from a memory corruption vulnerability in the /nova/bin/traceroute... |
| CVE-2020-20218 | MEDIUM | 6.5 | 2.0% | May 3, 2021 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute pro... |
| CVE-2020-28943 | MEDIUM | 6.5 | 1.2% | Apr 30, 2021 | OX App Suite 7.10.4 and earlier allows SSRF via a snippet. |
| CVE-2020-18084 | MEDIUM | 6.1 | 1.3% | Apr 30, 2021 | Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into t... |
| CVE-2020-1721 | MEDIUM | 6.1 | 1.0% | Apr 30, 2021 | A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitiz... |
| CVE-2020-18035 | MEDIUM | 6.1 | 1.0% | Apr 29, 2021 | Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into... |
| CVE-2020-15225 | MEDIUM | 6.5 | 1.8% | Apr 29, 2021 | django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before versi... |
| CVE-2020-22808 | MEDIUM | 6.1 | 0.8% | Apr 29, 2021 | An issue was found in yii2_fecshop 2.x. There is a reflected XSS vulnerability in the check cart page. |
| CVE-2020-21101 | MEDIUM | 5.4 | 0.6% | Apr 29, 2021 | Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite... |
| CVE-2020-22790 | MEDIUM | 5.4 | 1.3% | Apr 28, 2021 | Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby inject... |
| CVE-2020-22789 | MEDIUM | 6.1 | 1.2% | Apr 28, 2021 | Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileg... |
| CVE-2020-22783 | MEDIUM | 6.5 | 0.6% | Apr 28, 2021 | Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database ... |
| CVE-2020-18022 | MEDIUM | 6.1 | 1.2% | Apr 28, 2021 | Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtai... |
| CVE-2020-17999 | MEDIUM | 6.1 | 1.6% | Apr 28, 2021 | Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via ... |
| CVE-2020-21993 | MEDIUM | 6.1 | 0.8% | Apr 28, 2021 | In WEMS Limited Enterprise Manager 2.58, input passed to the GET parameter 'email' is not properly sanitized before bein... |
| CVE-2020-21998 | MEDIUM | 6.1 | 1.3% | Apr 27, 2021 | In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified befor... |
| CVE-2020-21987 | MEDIUM | 6.1 | 0.9% | Apr 27, 2021 | HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed v... |
| CVE-2020-4981 | MEDIUM | 6 | 0.2% | Apr 27, 2021 | IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now