2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29471 | MEDIUM | 4.8 | 1.3% | Dec 29, 2020 | OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as ... |
| CVE-2020-29470 | MEDIUM | 4.8 | 1.7% | Dec 29, 2020 | OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an... |
| CVE-2020-5806 | MEDIUM | 5.5 | 4.8% | Dec 29, 2020 | An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseL... |
| CVE-2020-29475 | MEDIUM | 4.8 | 1.1% | Dec 29, 2020 | nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability ca... |
| CVE-2020-13476 | MEDIUM | 4.8 | 0.7% | Dec 28, 2020 | NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module. |
| CVE-2020-13474 | MEDIUM | 6.5 | 0.7% | Dec 28, 2020 | In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-p... |
| CVE-2020-13473 | MEDIUM | 5.5 | 0.3% | Dec 28, 2020 | NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration... |
| CVE-2020-35730 | MEDIUM | 6.1 | 32.4% | Dec 28, 2020 | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attack... |
| CVE-2020-35615 | MEDIUM | 6.3 | 0.4% | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy... |
| CVE-2020-35614 | MEDIUM | 5.3 | 1.1% | Dec 28, 2020 | An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration a... |
| CVE-2020-27837 | MEDIUM | 6.4 | 0.2% | Dec 28, 2020 | A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it pos... |
| CVE-2020-15898 | MEDIUM | 5.3 | 1.0% | Dec 28, 2020 | In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability... |
| CVE-2020-26569 | MEDIUM | 5.9 | 0.8% | Dec 28, 2020 | In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result ... |
| CVE-2020-29245 | MEDIUM | 6.5 | 1.1% | Dec 28, 2020 | dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData. |
| CVE-2020-29244 | MEDIUM | 6.5 | 1.1% | Dec 28, 2020 | dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame. |
| CVE-2020-29243 | MEDIUM | 6.5 | 1.1% | Dec 28, 2020 | dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame. |
| CVE-2020-29242 | MEDIUM | 6.5 | 1.1% | Dec 28, 2020 | dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame. |
| CVE-2020-29159 | MEDIUM | 4.9 | 0.9% | Dec 28, 2020 | An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Ro... |
| CVE-2020-29158 | MEDIUM | 4.3 | 0.7% | Dec 28, 2020 | An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access... |
| CVE-2020-26035 | MEDIUM | 5.4 | 0.5% | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket. |
| CVE-2020-26034 | MEDIUM | 4.3 | 0.7% | Dec 28, 2020 | An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a wa... |
| CVE-2020-26033 | MEDIUM | 5.4 | 0.4% | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF tok... |
| CVE-2020-26031 | MEDIUM | 4.3 | 0.6% | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base ... |
| CVE-2020-26029 | MEDIUM | 6.5 | 0.8% | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On... |
| CVE-2020-26028 | MEDIUM | 4.9 | 0.9% | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now