2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-35275MEDIUM5.4Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to an...
CVE-2020-35274MEDIUM4.8DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attac...
CVE-2020-26049MEDIUM6.1Nifty-PM CPE 2.3 is affected by stored HTML injection. The impact is remote arbitrary code execution.
CVE-2020-35589MEDIUM5.4The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-logi...
CVE-2020-29447MEDIUM4.3Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of ...
CVE-2020-14271MEDIUM6.1HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling ...
CVE-2020-4080MEDIUM6.1HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of me...
CVE-2020-17520MEDIUM6.5In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verificat...
CVE-2020-20285MEDIUM5.4There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php
CVE-2020-26251MEDIUM4.7Open Zaak is a modern, open-source data- and services-layer to enable zaakgericht werken, a Dutch approach to case manag...
CVE-2020-4764MEDIUM6.5IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou...
CVE-2020-25901MEDIUM6.1Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious we...
CVE-2020-25495MEDIUM6.1A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote at...
CVE-2020-26178MEDIUM5.3In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments wit...
CVE-2020-26177MEDIUM4.3In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not int...
CVE-2020-26176MEDIUM4.3An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /ap...
CVE-2020-26175MEDIUM6.5In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in...
CVE-2020-26173MEDIUM4.3An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download docu...
CVE-2020-26172MEDIUM6.5Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse th...
CVE-2020-26171MEDIUM4.3In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can ...
CVE-2020-35552MEDIUM5.3An issue was discovered in the GPS daemon on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (non-Qualcomm chips...
CVE-2020-35549MEDIUM5.5An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Any application may establi...
CVE-2020-35548MEDIUM5.5An issue was discovered in Finder on Samsung mobile devices with Q(10.0) software. A call to a non-existent provider all...
CVE-2020-35480MEDIUM5.3An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts...
CVE-2020-35479MEDIUM6.1MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now