2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-5271MEDIUM6.1In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters i...
CVE-2020-5270MEDIUM6.1In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts ...
CVE-2020-5269MEDIUM6.1In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feat...
CVE-2020-5265MEDIUM6.1In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminAttributesGroups page. The problem ...
CVE-2020-5264MEDIUM6.1In PrestaShop before version 1.7.6.5, there is a reflected XSS while running the security compromised page. It allows an...
CVE-2020-11888MEDIUM6.1python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example,...
CVE-2020-5569HIGH8.4An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is s...
CVE-2020-11930MEDIUM6.1The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflan...
CVE-2020-11928CRITICAL9.8In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta...
CVE-2020-11895CRITICAL9.1Ming (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c.
CVE-2020-11894CRITICAL9.1Ming (aka libming) 0.4.8 has a heap-based buffer over-read (8 bytes) in the function decompileIF() in decompile.c.
CVE-2020-11887MEDIUM6.1svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document.
CVE-2020-11886HIGH8.1OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka the NodeListController) via snmpParm or s...
CVE-2020-11885HIGH7.2WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the X...
CVE-2020-5737MEDIUM5.4Stored XSS in Tenable.Sc before 5.14.0 could allow an authenticated remote attacker to craft a request to execute arbitr...
CVE-2020-5733MEDIUM6.1In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login pag...
CVE-2020-5732MEDIUM6.1In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page...
CVE-2020-5731MEDIUM6.1In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting.
CVE-2020-5730MEDIUM6.1In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.
CVE-2020-5729MEDIUM6.1In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which...
CVE-2020-5728MEDIUM6.1OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (suc...
CVE-2020-1751HIGH7An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifi...
CVE-2020-11883MEDIUM5.3In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpect...
CVE-2020-0082HIGH7.8In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe dese...
CVE-2020-0081HIGH7.8In finalize of AssetManager.java, there is possible memory corruption due to a double free. This could lead to local esc...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now