2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-35741MEDIUM6.1HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inj...
CVE-2020-35740MEDIUM6.1HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax ...
CVE-2020-26291MEDIUM6.5URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be sp...
CVE-2020-27534MEDIUM5.3util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-ch...
CVE-2020-28413MEDIUM6.5In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the A...
CVE-2020-26288MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm pac...
CVE-2020-29231MEDIUM5.4EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the A...
CVE-2020-29230MEDIUM6.1EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the A...
CVE-2020-28925MEDIUM5.3Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with ...
CVE-2020-28365MEDIUM6.1Sentrifugo 3.2 allows Stored Cross-Site Scripting (XSS) vulnerability by inserting a payload within the X-Forwarded-For ...
CVE-2020-26247MEDIUM4.3Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri befo...
CVE-2020-5811MEDIUM6.5An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, whi...
CVE-2020-5810MEDIUM5.4A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media c...
CVE-2020-5809MEDIUM5.4A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScr...
CVE-2020-35241MEDIUM4.8FlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component. This vulnerability can allow an...
CVE-2020-35240MEDIUM4.8FluxBB 1.5.11 is affected by cross-site scripting (XSS in the Blog Content component. This vulnerability can allow an at...
CVE-2020-29477MEDIUM4.8Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow...
CVE-2020-29469MEDIUM5.4WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacke...
CVE-2020-29233MEDIUM5.4WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allo...
CVE-2020-35850MEDIUM6.5An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product...
CVE-2020-35842MEDIUM5.4Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v...
CVE-2020-35840MEDIUM5.4Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v...
CVE-2020-35838MEDIUM4.8Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b...
CVE-2020-35837MEDIUM4.8Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b...
CVE-2020-35836MEDIUM4.8Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now