2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-28208MEDIUM5.3An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
CVE-2020-25678MEDIUM4.4A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be f...
CVE-2020-27262MEDIUM5.4Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 A stored cross-site scripting (XSS) vulnerability ex...
CVE-2020-27260MEDIUM5.3Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affe...
CVE-2020-4667MEDIUM4.3IBM Engineering Requirements Quality Assistant On-Premises could allow an authenticated user to obtain sensitive informa...
CVE-2020-4666MEDIUM5.4IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability all...
CVE-2020-4664MEDIUM5.4IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability all...
CVE-2020-4663MEDIUM5.4IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability all...
CVE-2020-4606MEDIUM4.4IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processin...
CVE-2020-25950MEDIUM4.3Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact...
CVE-2020-4897MEDIUM5.3IBM Emptoris Contract Management and IBM Emptoris Spend Analysis 10.1.0, 10.1.1, and 10.1.3 could allow a remote attacke...
CVE-2020-4896MEDIUM6.5IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validati...
CVE-2020-4895MEDIUM5.4IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This v...
CVE-2020-4893MEDIUM5.9IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request ...
CVE-2020-4892MEDIUM5.4IBM Emptoris Contract Management 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed ...
CVE-2020-27835MEDIUM4.4A use after free in the Linux kernel infiniband hfi1 driver in versions prior to 5.10-rc6 was found in the way user call...
CVE-2020-25680MEDIUM5.4A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore ...
CVE-2020-25476MEDIUM6.1Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user ...
CVE-2020-35111MEDIUM4.3When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not trigg...
CVE-2020-26979MEDIUM6.1When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes ca...
CVE-2020-26978MEDIUM6.1Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network'...
CVE-2020-26977MEDIUM6.5By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab wh...
CVE-2020-26976MEDIUM6.5When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service wo...
CVE-2020-26975MEDIUM6.5When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary header...
CVE-2020-26768MEDIUM6.1Formstone <=1.4.16 is vulnerable to a Reflected Cross-Site Scripting (XSS) vulnerability caused by improper validation o...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now