2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-27270MEDIUM5.7SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDa...
CVE-2020-4873MEDIUM5.3IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS poli...
CVE-2020-4871MEDIUM5.5IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-...
CVE-2020-28481MEDIUM4.3The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whi...
CVE-2020-23522MEDIUM6.8Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.
CVE-2020-20950MEDIUM5.9Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 201...
CVE-2020-29450MEDIUM6.5Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's avai...
CVE-2020-36192MEDIUM5.3An issue was discovered in the Source Integration plugin before 2.4.1 for MantisBT. An attacker can gain access to the S...
CVE-2020-7343MEDIUM5.5Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee p...
CVE-2020-28473MEDIUM6.8The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cl...
CVE-2020-29446MEDIUM5.3Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Ob...
CVE-2020-15864MEDIUM6.1An issue was discovered in Quali CloudShell 9.3. An XSS vulnerability in the login page allows an attacker to craft a UR...
CVE-2020-16255MEDIUM6.1ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'
CVE-2020-35748MEDIUM5.4Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37...
CVE-2020-26414MEDIUM6.5An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is wr...
CVE-2020-35582MEDIUM5.4A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitr...
CVE-2020-35581MEDIUM5.4A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitr...
CVE-2020-27219MEDIUM6.1In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API...
CVE-2020-16046MEDIUM6.1Script injection in iOSWeb in Google Chrome on iOS prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary...
CVE-2020-6777MEDIUM4.8A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAE...
CVE-2020-29587MEDIUM5.4SimplCommerce 1.0.0-rc uses the Bootbox.js library, which allows creation of programmatic dialog boxes using Bootstrap m...
CVE-2020-29019MEDIUM5.3A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow a remote,...
CVE-2020-27368MEDIUM5.5Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /ic...
CVE-2020-26733MEDIUM5.4Cross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 ...
CVE-2020-28470MEDIUM6.1This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() funct...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now