2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-9201MEDIUM6.5There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software re...
CVE-2020-9137MEDIUM6.7There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 an...
CVE-2020-9119MEDIUM6.2There is a privilege escalation vulnerability on some Huawei smart phones due to design defects. The attacker needs to p...
CVE-2020-35659MEDIUM6.1The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indir...
CVE-2020-27729MEDIUM6.1In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an u...
CVE-2020-27727MEDIUM4.9On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administra...
CVE-2020-27726MEDIUM6.1In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a reflected cross-sit...
CVE-2020-27722MEDIUM6.5In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin doe...
CVE-2020-27719MEDIUM6.1On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an u...
CVE-2020-28190MEDIUM5.9TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP...
CVE-2020-28185MEDIUM5.3User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid us...
CVE-2020-28184MEDIUM5.4Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitr...
CVE-2020-27725MEDIUM4.3In version 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 of BIG-IP DNS, GTM, and...
CVE-2020-27724MEDIUM6.5In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5....
CVE-2020-35677MEDIUM4.8BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator...
CVE-2020-35676MEDIUM6.1BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the se...
CVE-2020-35669MEDIUM6.1An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the ap...
CVE-2020-5684MEDIUM4.8iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not veri...
CVE-2020-2503MEDIUM5.4If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in Fi...
CVE-2020-35252MEDIUM6.1Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registra...
CVE-2020-28071MEDIUM4.8SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the a...
CVE-2020-13969MEDIUM6.1CRK Business Platform <= 2019.1 allows reflected XSS via erro.aspx on 'CRK', 'IDContratante', 'Erro', or 'Mod' parameter...
CVE-2020-4642MEDIUM5.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local atta...
CVE-2020-9439MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Owl Tin Canny LearnDash Reporting before 3.4.4 allows aut...
CVE-2020-6159MEDIUM6.1URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scr...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now