2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35275 | MEDIUM | 5.4 | 1.0% | Dec 21, 2020 | Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to an... |
| CVE-2020-35274 | MEDIUM | 4.8 | 0.6% | Dec 21, 2020 | DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attac... |
| CVE-2020-26049 | MEDIUM | 6.1 | 1.3% | Dec 21, 2020 | Nifty-PM CPE 2.3 is affected by stored HTML injection. The impact is remote arbitrary code execution. |
| CVE-2020-35589 | MEDIUM | 5.4 | 0.8% | Dec 21, 2020 | The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-logi... |
| CVE-2020-29447 | MEDIUM | 4.3 | 1.0% | Dec 21, 2020 | Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of ... |
| CVE-2020-14271 | MEDIUM | 6.1 | 1.1% | Dec 18, 2020 | HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling ... |
| CVE-2020-4080 | MEDIUM | 6.1 | 0.8% | Dec 18, 2020 | HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of me... |
| CVE-2020-17520 | MEDIUM | 6.5 | 1.3% | Dec 18, 2020 | In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verificat... |
| CVE-2020-20285 | MEDIUM | 5.4 | 1.6% | Dec 18, 2020 | There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php |
| CVE-2020-26251 | MEDIUM | 4.7 | 0.4% | Dec 18, 2020 | Open Zaak is a modern, open-source data- and services-layer to enable zaakgericht werken, a Dutch approach to case manag... |
| CVE-2020-4764 | MEDIUM | 6.5 | 0.4% | Dec 18, 2020 | IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou... |
| CVE-2020-25901 | MEDIUM | 6.1 | 5.1% | Dec 18, 2020 | Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious we... |
| CVE-2020-25495 | MEDIUM | 6.1 | 8.1% | Dec 18, 2020 | A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote at... |
| CVE-2020-26178 | MEDIUM | 5.3 | 0.9% | Dec 18, 2020 | In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments wit... |
| CVE-2020-26177 | MEDIUM | 4.3 | 0.6% | Dec 18, 2020 | In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not int... |
| CVE-2020-26176 | MEDIUM | 4.3 | 0.7% | Dec 18, 2020 | An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /ap... |
| CVE-2020-26175 | MEDIUM | 6.5 | 0.7% | Dec 18, 2020 | In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in... |
| CVE-2020-26173 | MEDIUM | 4.3 | 0.7% | Dec 18, 2020 | An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download docu... |
| CVE-2020-26172 | MEDIUM | 6.5 | 0.7% | Dec 18, 2020 | Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse th... |
| CVE-2020-26171 | MEDIUM | 4.3 | 0.6% | Dec 18, 2020 | In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can ... |
| CVE-2020-35552 | MEDIUM | 5.3 | 0.3% | Dec 18, 2020 | An issue was discovered in the GPS daemon on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (non-Qualcomm chips... |
| CVE-2020-35549 | MEDIUM | 5.5 | 0.1% | Dec 18, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Any application may establi... |
| CVE-2020-35548 | MEDIUM | 5.5 | 0.1% | Dec 18, 2020 | An issue was discovered in Finder on Samsung mobile devices with Q(10.0) software. A call to a non-existent provider all... |
| CVE-2020-35480 | MEDIUM | 5.3 | 1.5% | Dec 18, 2020 | An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts... |
| CVE-2020-35479 | MEDIUM | 6.1 | 1.5% | Dec 18, 2020 | MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now