2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-24085MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHo...
CVE-2020-23447MEDIUM6.1newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their a...
CVE-2020-23161MEDIUM6.5Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to ...
CVE-2020-23014MEDIUM5.4APfell 1.4 is vulnerable to authenticated reflected cross-site scripting (XSS) in /apiui/command_ through the payloadtyp...
CVE-2020-21147MEDIUM4.8RockOA V1.9.8 is affected by a cross-site scripting (XSS) vulnerability which allows remote attackers to send malicious ...
CVE-2020-21146MEDIUM6.1Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability. When the user name is inserted as JavaScript ...
CVE-2020-17522MEDIUM5.8When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0,...
CVE-2020-12514MEDIUM4.9Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a ...
CVE-2020-12512MEDIUM5.4Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site ...
CVE-2020-28487MEDIUM6.8This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline elem...
CVE-2020-8569MEDIUM6.5Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resour...
CVE-2020-8568MEDIUM6.5Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassP...
CVE-2020-8567MEDIUM6.5Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to...
CVE-2020-8554MEDIUM5Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.exter...
CVE-2020-4969MEDIUM5.9IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, c...
CVE-2020-4968MEDIUM6.5IBM Security Identity Governance and Intelligence 5.2.6 uses weaker than expected cryptographic algorithms that could al...
CVE-2020-4966MEDIUM4.3IBM Security Identity Governance and Intelligence 5.2.6 does not set the secure attribute on authorization tokens or ses...
CVE-2020-3687MEDIUM5.5Local privilege escalation in admin services in Windows environment can occur due to an arbitrary read issue.
CVE-2020-11183MEDIUM6.7A process can potentially cause a buffer overflow in the display service allowing privilege escalation by executing code...
CVE-2020-11152MEDIUM6.4Race condition in HAL layer while processing callback objects received from HIDL due to lack of synchronization between ...
CVE-2020-11151MEDIUM6.4Race condition occurs while calling user space ioctl from two different threads can results to use after free issue in v...
CVE-2020-11150MEDIUM6.7Out of bound memory access in camera driver due to improper validation on data coming from UMD which is used for offset ...
CVE-2020-11149MEDIUM6.7Out of bound access due to usage of an out-of-range pointer offset in the camera driver. in Snapdragon Auto, Snapdragon ...
CVE-2020-11148MEDIUM6.7Use after free issue in HIDL while using callback to post event in Rx thread when internal mutex is not acquired and mea...
CVE-2020-25687MEDIUM5.9A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is e...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now