2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-28644MEDIUM4.3The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against so...
CVE-2020-35943MEDIUM6.5A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (...
CVE-2020-35572MEDIUM6.1Adminer through 4.7.8 allows XSS via the history parameter to the default URI.
CVE-2020-28394MEDIUM5.5A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1....
CVE-2020-28388MEDIUM5.3A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether...
CVE-2020-16144MEDIUM5.7When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous us...
CVE-2020-27008MEDIUM5.5A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1....
CVE-2020-27007MEDIUM5.5A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1....
CVE-2020-27004MEDIUM5.5A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1....
CVE-2020-26998MEDIUM5.5A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1....
CVE-2020-10048MEDIUM5.5A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an ...
CVE-2020-4996MEDIUM5.5IBM Security Identity Governance and Intelligence 5.2.6 could allow a local user to obtain sensitive information via the...
CVE-2020-4995MEDIUM5.3IBM Security Identity Governance and Intelligence 5.2.6 does not invalidate session after logout which could allow a use...
CVE-2020-4791MEDIUM5.3IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using ma...
CVE-2020-4790MEDIUM6.5IBM Security Identity Governance and Intelligence 5.2.6 could allow a user to cause a denial of service due to improperl...
CVE-2020-22841MEDIUM4.8Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution...
CVE-2020-22840MEDIUM6.1Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redi...
CVE-2020-13462MEDIUM5.7Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in...
CVE-2020-13461MEDIUM4.3Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided...
CVE-2020-13409MEDIUM5.9Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is als...
CVE-2020-13408MEDIUM5.9Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is als...
CVE-2020-13407MEDIUM5.9Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is als...
CVE-2020-29021MEDIUM4.8A vulnerability in web UI input field of GateManager allows authenticated attacker to enter script tags that could cause...
CVE-2020-14391MEDIUM5.5A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly us...
CVE-2020-8587MEDIUM5.5OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that cou...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now