2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24903 | MEDIUM | 6.1 | 2.9% | Jan 7, 2021 | Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user ... |
| CVE-2020-24902 | MEDIUM | 6.1 | 2.9% | Jan 7, 2021 | Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied ... |
| CVE-2020-24901 | MEDIUM | 6.1 | 1.0% | Jan 7, 2021 | The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remot... |
| CVE-2020-24900 | MEDIUM | 6.1 | 0.9% | Jan 7, 2021 | The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load i... |
| CVE-2020-35262 | MEDIUM | 6.1 | 1.1% | Jan 6, 2021 | Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date ... |
| CVE-2020-25498 | MEDIUM | 4.8 | 1.1% | Jan 6, 2021 | Cross Site Scripting (XSS) vulnerability in Beetel router 777VR1 can be exploited via the NTP server name in System Time... |
| CVE-2020-8287 | MEDIUM | 6.5 | 16.3% | Jan 6, 2021 | Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for exa... |
| CVE-2020-8281 | MEDIUM | 5.4 | 0.6% | Jan 6, 2021 | A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform c... |
| CVE-2020-8280 | MEDIUM | 5.4 | 0.6% | Jan 6, 2021 | A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perfor... |
| CVE-2020-8275 | MEDIUM | 4.3 | 1.9% | Jan 6, 2021 | Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to re... |
| CVE-2020-8274 | MEDIUM | 6.5 | 2.0% | Jan 6, 2021 | Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by ... |
| CVE-2020-8264 | MEDIUM | 6.1 | 70.7% | Jan 6, 2021 | In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allow... |
| CVE-2020-29041 | MEDIUM | 5.3 | 1.4% | Jan 6, 2021 | A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the app... |
| CVE-2020-27283 | MEDIUM | 5.3 | 0.9% | Jan 6, 2021 | An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arb... |
| CVE-2020-8160 | MEDIUM | 6.1 | 0.7% | Jan 6, 2021 | MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scriptin... |
| CVE-2020-36175 | MEDIUM | 5.3 | 1.2% | Jan 6, 2021 | The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field. |
| CVE-2020-36174 | MEDIUM | 6.5 | 0.6% | Jan 6, 2021 | The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration. |
| CVE-2020-36173 | MEDIUM | 5.3 | 1.1% | Jan 6, 2021 | The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields. |
| CVE-2020-36172 | MEDIUM | 6.1 | 0.9% | Jan 6, 2021 | The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, p... |
| CVE-2020-36171 | MEDIUM | 6.1 | 0.8% | Jan 6, 2021 | The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads. |
| CVE-2020-36170 | MEDIUM | 5.3 | 1.1% | Jan 6, 2021 | The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms. |
| CVE-2020-4336 | MEDIUM | 5.3 | 1.0% | Jan 6, 2021 | IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosur... |
| CVE-2020-7336 | MEDIUM | 6.5 | 0.5% | Jan 5, 2021 | Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prio... |
| CVE-2020-35170 | MEDIUM | 5.4 | 0.6% | Jan 5, 2021 | Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, a... |
| CVE-2020-29502 | MEDIUM | 6.7 | 0.2% | Jan 5, 2021 | Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now