2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-29471MEDIUM4.8OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as ...
CVE-2020-29470MEDIUM4.8OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an...
CVE-2020-5806MEDIUM5.5An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseL...
CVE-2020-29475MEDIUM4.8nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability ca...
CVE-2020-13476MEDIUM4.8NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.
CVE-2020-13474MEDIUM6.5In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-p...
CVE-2020-13473MEDIUM5.5NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration...
CVE-2020-35730MEDIUM6.1An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attack...
CVE-2020-35615MEDIUM6.3An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy...
CVE-2020-35614MEDIUM5.3An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration a...
CVE-2020-27837MEDIUM6.4A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it pos...
CVE-2020-15898MEDIUM5.3In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability...
CVE-2020-26569MEDIUM5.9In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result ...
CVE-2020-29245MEDIUM6.5dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData.
CVE-2020-29244MEDIUM6.5dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame.
CVE-2020-29243MEDIUM6.5dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame.
CVE-2020-29242MEDIUM6.5dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame.
CVE-2020-29159MEDIUM4.9An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Ro...
CVE-2020-29158MEDIUM4.3An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access...
CVE-2020-26035MEDIUM5.4An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.
CVE-2020-26034MEDIUM4.3An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a wa...
CVE-2020-26033MEDIUM5.4An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF tok...
CVE-2020-26031MEDIUM4.3An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base ...
CVE-2020-26029MEDIUM6.5An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On...
CVE-2020-26028MEDIUM4.9An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now