2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-29193MEDIUM6.8Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which is just the asdf keyboa...
CVE-2020-28096MEDIUM6.8FOSCAM FHD X1 1.14.2.4 devices allow attackers (with physical UART access) to login via the ipc.fos~ password.
CVE-2020-35738MEDIUM6.1WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a mallo...
CVE-2020-29156MEDIUM5.3The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the...
CVE-2020-29250MEDIUM6.1CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php.
CVE-2020-29249MEDIUM6.1CXUUCMS V3 allows class="layui-input" XSS.
CVE-2020-29204MEDIUM6.1XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/j...
CVE-2020-35678MEDIUM6.1Autobahn|Python before 20.12.3 allows redirect header injection.
CVE-2020-28759MEDIUM5.5The serializer module in OAID Tengine lite-v1.0 has a Buffer Overflow and crash. NOTE: another person has stated "I don'...
CVE-2020-35437MEDIUM6.1Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the...
CVE-2020-35349MEDIUM4.8Savsoft Quiz 5 is affected by: Cross Site Scripting (XSS) via field_title (aka a title on the custom fields page).
CVE-2020-35347MEDIUM6.5CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.
CVE-2020-35346MEDIUM4.8CXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script ...
CVE-2020-20412MEDIUM6.5lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds ...
CVE-2020-29385MEDIUM5.5GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write...
CVE-2020-29172MEDIUM6.1A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via...
CVE-2020-27515MEDIUM6.1A Cross Site Scripting (XSS) vulnerability in Savsoft Quiz v5.0 allows remote attackers to inject arbitrary web script o...
CVE-2020-35710MEDIUM5.3Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submissi...
CVE-2020-35709MEDIUM4.9bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../me...
CVE-2020-35707MEDIUM5.4Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.
CVE-2020-35706MEDIUM5.4Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen.
CVE-2020-35705MEDIUM5.4Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen.
CVE-2020-35704MEDIUM5.4Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen.
CVE-2020-29247MEDIUM4.8WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in ...
CVE-2020-9202MEDIUM4.4There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to th...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now