2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-4673MEDIUM4.3IBM Workload Automation 9.5 stores sensitive information in HTML comments that could aid in further attacks against the ...
CVE-2020-26713MEDIUM6.1REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by th...
CVE-2020-25657MEDIUM5.9A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the...
CVE-2020-35655MEDIUM5.4In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because off...
CVE-2020-24701MEDIUM6.1OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
CVE-2020-24700MEDIUM5.4OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconf...
CVE-2020-23631MEDIUM6.1Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-si...
CVE-2020-26298MEDIUM5.4Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerabil...
CVE-2020-24025MEDIUM5.3Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specify...
CVE-2020-4869MEDIUM6.5IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflow. A remote attacker...
CVE-2020-25659MEDIUM5.9python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing o...
CVE-2020-23849MEDIUM6.1Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript.
CVE-2020-23644MEDIUM6.1XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php.
CVE-2020-23643MEDIUM6.1XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php.
CVE-2020-26800MEDIUM5.5A stack overflow vulnerability in Aleth Ethereum C++ client version <= 1.8.0 using a specially crafted a config.json fil...
CVE-2020-13922MEDIUM6.5Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users p...
CVE-2020-35727MEDIUM5.4Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...
CVE-2020-35726MEDIUM6.1Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...
CVE-2020-35725MEDIUM6.1Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...
CVE-2020-35724MEDIUM5.4Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...
CVE-2020-35723MEDIUM5.4Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...
CVE-2020-35722MEDIUM6.5CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/cr...
CVE-2020-35721MEDIUM5.4Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...
CVE-2020-35720MEDIUM5.4Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first...
CVE-2020-35719MEDIUM6.1Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now