2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-35230MEDIUM6.8Multiple integer overflow parameters were found in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 d...
CVE-2020-35228MEDIUM4.8A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 device...
CVE-2020-35225MEDIUM6.8The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length o...
CVE-2020-35224MEDIUM6.5A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 device...
CVE-2020-5016MEDIUM6.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the sys...
CVE-2020-4717MEDIUM5.5A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permissio...
CVE-2020-35752MEDIUM5.4Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post tit...
CVE-2020-28705MEDIUM4.3FUEL CMS 1.4.13 contains a cross-site request forgery (CSRF) vulnerability that can delete a page via a post ID to /page...
CVE-2020-23721MEDIUM5.4An issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages...
CVE-2020-13959MEDIUM6.1The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered...
CVE-2020-35522MEDIUM5.5In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting ...
CVE-2020-35521MEDIUM5.5A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort,...
CVE-2020-28150MEDIUM6.1I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an exter...
CVE-2020-8357MEDIUM5.5A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow conf...
CVE-2020-8356MEDIUM4.9An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, fo...
CVE-2020-35451MEDIUM4.7There is a race condition in OozieSharelibCLI in Apache Oozie before version 5.2.1 which allows a malicious attacker to ...
CVE-2020-27838MEDIUM6.5A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information a...
CVE-2020-27576MEDIUM5.4Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site scripting (XSS). Users are able to create folders in the web ap...
CVE-2020-5014MEDIUM6.7IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary cod...
CVE-2020-4903MEDIUM6.5IBM API Connect V10 and V2018 could allow an attacker who has intercepted a registration invitation link to impersonate ...
CVE-2020-29029MEDIUM6.1Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker...
CVE-2020-29028MEDIUM6.1Cross-site Scripting (XSS) vulnerability in web GUI of Secomea GateManager allows an attacker to inject arbitrary javasc...
CVE-2020-35594MEDIUM6.1Zoho ManageEngine ADManager Plus before 7066 allows XSS.
CVE-2020-25639MEDIUM4.4A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5....
CVE-2020-4975MEDIUM5.4IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now