2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8952MEDIUM6.1Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the logout.jsp timeOut parameter.
CVE-2020-8951MEDIUM5.4Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the Source or Destination field of the C...
CVE-2020-9337MEDIUM6.5In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.
CVE-2020-9407MEDIUM5.3IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COO...
CVE-2020-9406CRITICAL9.8IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
CVE-2020-9405MEDIUM6.1IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.
CVE-2020-9398CRITICAL9.8ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQ...
CVE-2020-9394HIGH8.8An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.
CVE-2020-9393MEDIUM6.1An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.
CVE-2020-9379MEDIUM6.5The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB4962...
CVE-2020-8810HIGH8.1An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify ...
CVE-2020-8809HIGH8.1Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connect...
CVE-2020-9391MEDIUM5.5An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top by...
CVE-2020-9019MEDIUM6.1The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Descr...
CVE-2020-9018MEDIUM5.3LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.
CVE-2020-9008MEDIUM5.4Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web...
CVE-2020-9335MEDIUM4.8Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploita...
CVE-2020-9334MEDIUM5.4A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitatio...
CVE-2020-9017HIGH8LiteCart through 2.2.1 allows CSV injection via a customer's profile.
CVE-2020-8794CRITICAL9.8OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult...
CVE-2020-8793MEDIUM4.7OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combi...
CVE-2020-9383HIGH7.1An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_re...
CVE-2020-8819HIGH8.1An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in...
CVE-2020-8818HIGH8.1An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in t...
CVE-2020-9385HIGH7.5A NULL Pointer Dereference exists in libzint in Zint 2.7.1 because multiple + characters are mishandled in add_on in upc...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now