2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-4866MEDIUM5.4IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java...
CVE-2020-4863MEDIUM5.4IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-4857MEDIUM5.4IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-4856MEDIUM5.4IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-35329MEDIUM6.5Courier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '.
CVE-2020-35328MEDIUM5.4Courier Management System 1.0 - 'First Name' Stored XSS
CVE-2020-35327MEDIUM6.5SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST...
CVE-2020-24912MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQ...
CVE-2020-8296MEDIUM6.7Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
CVE-2020-28591MEDIUM6.5An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libsli...
CVE-2020-27749MEDIUM6.7A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line in...
CVE-2020-15937MEDIUM6.1An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow...
CVE-2020-12530MEDIUM6.1An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There ...
CVE-2020-12529MEDIUM5.3An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There i...
CVE-2020-12527MEDIUM6.5An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all ve...
CVE-2020-4719MEDIUM4.9The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management ...
CVE-2020-23518MEDIUM5.4Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to vers...
CVE-2020-25902MEDIUM6.1Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execu...
CVE-2020-1936MEDIUM6.1A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.
CVE-2020-36240MEDIUM5.3The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthe...
CVE-2020-9479MEDIUM5.5When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory....
CVE-2020-7929MEDIUM6.5A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a...
CVE-2020-28972MEDIUM5.9In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) do...
CVE-2020-27618MEDIUM5.5The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input ...
CVE-2020-27223MEDIUM5.3In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request contai...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now