2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-35542MEDIUM5.4Unisys Data Exchange Management Studio through 5.0.34 doesn't sanitize the input to a HTML document field. This could be...
CVE-2020-4562MEDIUM5.3IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by allowing cross-window commun...
CVE-2020-7036MEDIUM6.5An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain rea...
CVE-2020-7035MEDIUM6.5An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could a...
CVE-2020-17542MEDIUM5.4Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious p...
CVE-2020-36319MEDIUM6.5Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 thr...
CVE-2020-27737MEDIUM6.5A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether...
CVE-2020-27736MEDIUM6.5A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether...
CVE-2020-25243MEDIUM5.1A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be trigg...
CVE-2020-36324MEDIUM6.1Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the ...
CVE-2020-23932MEDIUM5.5An issue was discovered in gpac before 1.0.1. A NULL pointer dereference exists in the function dump_isom_sdp located in...
CVE-2020-23930MEDIUM5.5An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function nhmldump_send_header...
CVE-2020-23915MEDIUM5.5An issue was discovered in cpp-peglib through v0.1.12. peg::resolve_escape_sequence() in peglib.h has a heap-based buffe...
CVE-2020-23914MEDIUM5.5An issue was discovered in cpp-peglib through v0.1.12. A NULL pointer dereference exists in the peg::AstOptimizer::optim...
CVE-2020-23912MEDIUM5.5An issue was discovered in Bento4 through v1.6.0-637. A NULL pointer dereference exists in the function AP4_StszAtom::Ge...
CVE-2020-25864MEDIUM6.1HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scriptin...
CVE-2020-14105MEDIUM5.5The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.
CVE-2020-28141MEDIUM5.4The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated us...
CVE-2020-9681MEDIUM6.5Adobe Genuine Service version 6.6 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An aut...
CVE-2020-9667MEDIUM6.5Adobe Genuine Service version 6.6 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An aut...
CVE-2020-28898MEDIUM5.3In QED ResourceXpress through 4.9k, a large numeric or alphanumeric value submitted in specific URL parameters causes a ...
CVE-2020-7308MEDIUM6.5Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Febru...
CVE-2020-7270MEDIUM4.3Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows re...
CVE-2020-7269MEDIUM4.3Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows re...
CVE-2020-36288MEDIUM6.1The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before ver...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now