2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-35272MEDIUM4.8Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in t...
CVE-2020-35271MEDIUM4.8Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in t...
CVE-2020-25683MEDIUM5.9A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is e...
CVE-2020-20949MEDIUM5.9Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for S...
CVE-2020-4887MEDIUM5.5IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore user command to cre...
CVE-2020-27852MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allo...
CVE-2020-27851MEDIUM5.4Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketg...
CVE-2020-27850MEDIUM4.8A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 al...
CVE-2020-13134MEDIUM4.8Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires a...
CVE-2020-13133MEDIUM6.1Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires a...
CVE-2020-25385MEDIUM6.1Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapsho...
CVE-2020-19363MEDIUM6.5Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directori...
CVE-2020-19362MEDIUM6.1Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performi...
CVE-2020-19361MEDIUM6.1Reflected XSS in Medintux v2.16.000 CCAM.php by manipulating the mot1 parameter can result in an attacker performing mal...
CVE-2020-28707MEDIUM6.1The Stockdio Historical Chart plugin before 2.8.1 for WordPress is affected by Cross Site Scripting (XSS) via stockdio_c...
CVE-2020-27269MEDIUM5.7In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and...
CVE-2020-27268MEDIUM6.5In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin...
CVE-2020-27266MEDIUM6.5In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin...
CVE-2020-11997MEDIUM4.3Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. I...
CVE-2020-27258MEDIUM6.5In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the com...
CVE-2020-27256MEDIUM6.8In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu o...
CVE-2020-14410MEDIUM5.4SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in vi...
CVE-2020-8581MEDIUM6.5Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authentica...
CVE-2020-27276MEDIUM5.7SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyD...
CVE-2020-27272MEDIUM5.7SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now