2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-4883MEDIUM6.5IBM QRadar SIEM 7.3 and 7.4 could disclose sensitive information about other domains which could be used in further atta...
CVE-2020-13662MEDIUM6.1Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which woul...
CVE-2020-13666MEDIUM6.1Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XS...
CVE-2020-22428MEDIUM4.8SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an a...
CVE-2020-4987MEDIUM5.4The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and pr...
CVE-2020-23015MEDIUM6.1An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not fil...
CVE-2020-28945MEDIUM6.1OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as ![](http://oner...
CVE-2020-20247MEDIUM6.5Mikrotik RouterOs before 6.46.5 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute...
CVE-2020-20218MEDIUM6.5Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute pro...
CVE-2020-28943MEDIUM6.5OX App Suite 7.10.4 and earlier allows SSRF via a snippet.
CVE-2020-18084MEDIUM6.1Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into t...
CVE-2020-1721MEDIUM6.1A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitiz...
CVE-2020-18035MEDIUM6.1Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into...
CVE-2020-15225MEDIUM6.5django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before versi...
CVE-2020-22808MEDIUM6.1An issue was found in yii2_fecshop 2.x. There is a reflected XSS vulnerability in the check cart page.
CVE-2020-21101MEDIUM5.4Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite...
CVE-2020-22790MEDIUM5.4Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby inject...
CVE-2020-22789MEDIUM6.1Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileg...
CVE-2020-22783MEDIUM6.5Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database ...
CVE-2020-18022MEDIUM6.1Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtai...
CVE-2020-17999MEDIUM6.1Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via ...
CVE-2020-21993MEDIUM6.1In WEMS Limited Enterprise Manager 2.58, input passed to the GET parameter 'email' is not properly sanitized before bein...
CVE-2020-21998MEDIUM6.1In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified befor...
CVE-2020-21987MEDIUM6.1HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed v...
CVE-2020-4981MEDIUM6IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now