2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35741 | MEDIUM | 6.1 | 0.6% | Dec 31, 2020 | HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inj... |
| CVE-2020-35740 | MEDIUM | 6.1 | 0.6% | Dec 31, 2020 | HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax ... |
| CVE-2020-26291 | MEDIUM | 6.5 | 1.7% | Dec 31, 2020 | URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be sp... |
| CVE-2020-27534 | MEDIUM | 5.3 | 1.7% | Dec 30, 2020 | util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-ch... |
| CVE-2020-28413 | MEDIUM | 6.5 | 4.9% | Dec 30, 2020 | In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the A... |
| CVE-2020-26288 | MEDIUM | 6.5 | 0.8% | Dec 30, 2020 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm pac... |
| CVE-2020-29231 | MEDIUM | 5.4 | 0.6% | Dec 30, 2020 | EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the A... |
| CVE-2020-29230 | MEDIUM | 6.1 | 0.8% | Dec 30, 2020 | EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the A... |
| CVE-2020-28925 | MEDIUM | 5.3 | 1.1% | Dec 30, 2020 | Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with ... |
| CVE-2020-28365 | MEDIUM | 6.1 | 0.7% | Dec 30, 2020 | Sentrifugo 3.2 allows Stored Cross-Site Scripting (XSS) vulnerability by inserting a payload within the X-Forwarded-For ... |
| CVE-2020-26247 | MEDIUM | 4.3 | 1.3% | Dec 30, 2020 | Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri befo... |
| CVE-2020-5811 | MEDIUM | 6.5 | 9.4% | Dec 30, 2020 | An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, whi... |
| CVE-2020-5810 | MEDIUM | 5.4 | 66.2% | Dec 30, 2020 | A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media c... |
| CVE-2020-5809 | MEDIUM | 5.4 | 0.7% | Dec 30, 2020 | A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScr... |
| CVE-2020-35241 | MEDIUM | 4.8 | 2.1% | Dec 30, 2020 | FlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component. This vulnerability can allow an... |
| CVE-2020-35240 | MEDIUM | 4.8 | 1.0% | Dec 30, 2020 | FluxBB 1.5.11 is affected by cross-site scripting (XSS in the Blog Content component. This vulnerability can allow an at... |
| CVE-2020-29477 | MEDIUM | 4.8 | 1.1% | Dec 30, 2020 | Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow... |
| CVE-2020-29469 | MEDIUM | 5.4 | 1.4% | Dec 30, 2020 | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacke... |
| CVE-2020-29233 | MEDIUM | 5.4 | 1.3% | Dec 30, 2020 | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allo... |
| CVE-2020-35850 | MEDIUM | 6.5 | 1.6% | Dec 30, 2020 | An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product... |
| CVE-2020-35842 | MEDIUM | 5.4 | 0.5% | Dec 30, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v... |
| CVE-2020-35840 | MEDIUM | 5.4 | 0.5% | Dec 30, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v... |
| CVE-2020-35838 | MEDIUM | 4.8 | 0.6% | Dec 30, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
| CVE-2020-35837 | MEDIUM | 4.8 | 0.7% | Dec 30, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
| CVE-2020-35836 | MEDIUM | 4.8 | 0.6% | Dec 30, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now