2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-29451MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Info...
CVE-2020-36237MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field o...
CVE-2020-36236MEDIUM6.1Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript...
CVE-2020-36235MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field a...
CVE-2020-36234MEDIUM4.8Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript...
CVE-2020-27867MEDIUM6.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R602...
CVE-2020-27863MEDIUM6.5This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Li...
CVE-2020-9307MEDIUM6.5Hirschmann OS2, RSP, and RSPE devices before HiOS 08.3.00 allow a denial of service. An unauthenticated, adjacent attack...
CVE-2020-13186MEDIUM6.5An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web f...
CVE-2020-13185MEDIUM6.5Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were acce...
CVE-2020-4768MEDIUM5.4IBM Case Manager 5.2 and 5.3 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scri...
CVE-2020-8030MEDIUM4.4A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to leak the bootstrapT...
CVE-2020-8029MEDIUM4A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local at...
CVE-2020-8027MEDIUM6.6A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Serv...
CVE-2020-8031MEDIUM5.4A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Servi...
CVE-2020-27870MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Ori...
CVE-2020-24842MEDIUM6.1PNPSCADA 2.200816204020 allows cross-site scripting (XSS), which can execute arbitrary JavaScript in the victim's browse...
CVE-2020-8355MEDIUM4.9An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows...
CVE-2020-16120MEDIUM4.4Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from...
CVE-2020-13565MEDIUM6.1An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and O...
CVE-2020-7021MEDIUM4.9Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_req...
CVE-2020-29171MEDIUM6.1Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP...
CVE-2020-26196MEDIUM5.5Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation issue. A user with the ...
CVE-2020-26195MEDIUM5.3Dell EMC PowerScale OneFS versions 8.1.2 – 9.1.0 contain an issue where the OneFS SMB directory auto-create may erroneou...
CVE-2020-22839MEDIUM6.1Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allow...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now