2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-24903MEDIUM6.1Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user ...
CVE-2020-24902MEDIUM6.1Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied ...
CVE-2020-24901MEDIUM6.1The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remot...
CVE-2020-24900MEDIUM6.1The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load i...
CVE-2020-35262MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date ...
CVE-2020-25498MEDIUM4.8Cross Site Scripting (XSS) vulnerability in Beetel router 777VR1 can be exploited via the NTP server name in System Time...
CVE-2020-8287MEDIUM6.5Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for exa...
CVE-2020-8281MEDIUM5.4A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform c...
CVE-2020-8280MEDIUM5.4A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perfor...
CVE-2020-8275MEDIUM4.3Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to re...
CVE-2020-8274MEDIUM6.5Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by ...
CVE-2020-8264MEDIUM6.1In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allow...
CVE-2020-29041MEDIUM5.3A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the app...
CVE-2020-27283MEDIUM5.3An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arb...
CVE-2020-8160MEDIUM6.1MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scriptin...
CVE-2020-36175MEDIUM5.3The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
CVE-2020-36174MEDIUM6.5The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
CVE-2020-36173MEDIUM5.3The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
CVE-2020-36172MEDIUM6.1The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, p...
CVE-2020-36171MEDIUM6.1The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.
CVE-2020-36170MEDIUM5.3The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.
CVE-2020-4336MEDIUM5.3IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosur...
CVE-2020-7336MEDIUM6.5Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prio...
CVE-2020-35170MEDIUM5.4Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, a...
CVE-2020-29502MEDIUM6.7Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now