2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5271 | MEDIUM | 6.1 | 0.8% | Apr 20, 2020 | In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters i... |
| CVE-2020-5270 | MEDIUM | 6.1 | 0.8% | Apr 20, 2020 | In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts ... |
| CVE-2020-5269 | MEDIUM | 6.1 | 0.8% | Apr 20, 2020 | In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feat... |
| CVE-2020-5265 | MEDIUM | 6.1 | 0.7% | Apr 20, 2020 | In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminAttributesGroups page. The problem ... |
| CVE-2020-5264 | MEDIUM | 6.1 | 0.7% | Apr 20, 2020 | In PrestaShop before version 1.7.6.5, there is a reflected XSS while running the security compromised page. It allows an... |
| CVE-2020-11888 | MEDIUM | 6.1 | 1.9% | Apr 20, 2020 | python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example,... |
| CVE-2020-5569 | HIGH | 8.4 | 0.3% | Apr 20, 2020 | An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is s... |
| CVE-2020-11930 | MEDIUM | 6.1 | 4.5% | Apr 20, 2020 | The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflan... |
| CVE-2020-11928 | CRITICAL | 9.8 | 3.6% | Apr 20, 2020 | In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta... |
| CVE-2020-11895 | CRITICAL | 9.1 | 1.7% | Apr 19, 2020 | Ming (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c. |
| CVE-2020-11894 | CRITICAL | 9.1 | 1.7% | Apr 19, 2020 | Ming (aka libming) 0.4.8 has a heap-based buffer over-read (8 bytes) in the function decompileIF() in decompile.c. |
| CVE-2020-11887 | MEDIUM | 6.1 | 0.7% | Apr 17, 2020 | svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document. |
| CVE-2020-11886 | HIGH | 8.1 | 1.4% | Apr 17, 2020 | OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka the NodeListController) via snmpParm or s... |
| CVE-2020-11885 | HIGH | 7.2 | 0.8% | Apr 17, 2020 | WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the X... |
| CVE-2020-5737 | MEDIUM | 5.4 | 0.6% | Apr 17, 2020 | Stored XSS in Tenable.Sc before 5.14.0 could allow an authenticated remote attacker to craft a request to execute arbitr... |
| CVE-2020-5733 | MEDIUM | 6.1 | 1.2% | Apr 17, 2020 | In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login pag... |
| CVE-2020-5732 | MEDIUM | 6.1 | 1.2% | Apr 17, 2020 | In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page... |
| CVE-2020-5731 | MEDIUM | 6.1 | 1.1% | Apr 17, 2020 | In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting. |
| CVE-2020-5730 | MEDIUM | 6.1 | 1.1% | Apr 17, 2020 | In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting. |
| CVE-2020-5729 | MEDIUM | 6.1 | 1.1% | Apr 17, 2020 | In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which... |
| CVE-2020-5728 | MEDIUM | 6.1 | 1.1% | Apr 17, 2020 | OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (suc... |
| CVE-2020-1751 | HIGH | 7 | 0.5% | Apr 17, 2020 | An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifi... |
| CVE-2020-11883 | MEDIUM | 5.3 | 15.2% | Apr 17, 2020 | In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpect... |
| CVE-2020-0082 | HIGH | 7.8 | 0.4% | Apr 17, 2020 | In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe dese... |
| CVE-2020-0081 | HIGH | 7.8 | 0.2% | Apr 17, 2020 | In finalize of AssetManager.java, there is possible memory corruption due to a double free. This could lead to local esc... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now