2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-4828MEDIUM6.5IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, cause...
CVE-2020-4827MEDIUM4.3IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery...
CVE-2020-4826MEDIUM4.3IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery...
CVE-2020-4825MEDIUM5.4IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site scripting. This...
CVE-2020-4640MEDIUM4.1Certain IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 configurations can result in sensit...
CVE-2020-27873MEDIUM6.5This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG...
CVE-2020-16194MEDIUM5.3An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated at...
CVE-2020-14247MEDIUM6.5HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to...
CVE-2020-9390MEDIUM5.4SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content...
CVE-2020-9388MEDIUM6.5CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administ...
CVE-2020-18724MEDIUM5.4Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19...
CVE-2020-18723MEDIUM5.4Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code ...
CVE-2020-8294MEDIUM5.4A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack usi...
CVE-2020-35482MEDIUM5.4SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.
CVE-2020-29582MEDIUM5.3In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker wa...
CVE-2020-28001MEDIUM5.4SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.
CVE-2020-27994MEDIUM6.5SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.
CVE-2020-25208MEDIUM5.3In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permiss...
CVE-2020-29164MEDIUM6.1PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).
CVE-2020-24490MEDIUM6.5Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adja...
CVE-2020-8734MEDIUM6.7Improper input validation in the firmware for Intel(R) Server Board M10JNP2SB before version 7.210 may allow a privilege...
CVE-2020-4081MEDIUM6.1In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).
CVE-2020-29662MEDIUM5.3In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.
CVE-2020-14221MEDIUM4.9HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.
CVE-2020-28498MEDIUM6.8The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now