2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-28401MEDIUM6.5An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori...
CVE-2020-8585MEDIUM5.5OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorize...
CVE-2020-36115MEDIUM5.4Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf ...
CVE-2020-1725MEDIUM5.4A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changi...
CVE-2020-1723MEDIUM6.1A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbi...
CVE-2020-26272MEDIUM6.5The Electron framework lets users write cross-platform desktop applications using JavaScript, HTML and CSS. In versions ...
CVE-2020-5428MEDIUM6In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising cert...
CVE-2020-4865MEDIUM5.4IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J...
CVE-2020-4855MEDIUM5.4IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J...
CVE-2020-4789MEDIUM6.5IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 could allow a remote attac...
CVE-2020-4786MEDIUM4.3IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vulnerable to server si...
CVE-2020-4547MEDIUM5.4IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a ...
CVE-2020-4524MEDIUM5.4IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J...
CVE-2020-4189MEDIUM4.3IBM Security Guardium 11.2 discloses sensitive information in the response headers that could be used in further attacks...
CVE-2020-4967MEDIUM4.3IBM Cloud Pak for Security (CP4S) 1.3.0.1 could disclose sensitive information through HTTP headers which could be used ...
CVE-2020-4820MEDIUM6.1IBM Cloud Pak for Security (CP4S) 1.4.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2020-4816MEDIUM5.9IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the f...
CVE-2020-4815MEDIUM5.3IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote user to obtain sensitive information from HTTP response h...
CVE-2020-4628MEDIUM5.3IBM Cloud Pak for Security (CP4S) 1.3.0.1 and 1.4.0.0 could allow a remote attacker to obtain sensitive information when...
CVE-2020-36012MEDIUM4.8Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary ...
CVE-2020-23774MEDIUM6.1A reflected XSS vulnerability exists in tohtml/convert.php of Winmail 6.5, which can cause JavaScript code to be execute...
CVE-2020-8293MEDIUM6.5A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in wo...
CVE-2020-8292MEDIUM5.4Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop fun...
CVE-2020-8288MEDIUM5.4The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability...
CVE-2020-6780MEDIUM4.9Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now