2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-27010MEDIUM4.8A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow a...
CVE-2020-4845MEDIUM5.4IBM Security Key Lifecycle Manager 3.0.1 and 4.0 is vulnerable to cross-site scripting. This vulnerability allows users ...
CVE-2020-15293MEDIUM5.5Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to ins...
CVE-2020-15292MEDIUM5.5Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, Int...
CVE-2020-35453MEDIUM5.3HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibl...
CVE-2020-35177MEDIUM5.3HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in...
CVE-2020-35123MEDIUM6.5In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in ...
CVE-2020-29436MEDIUM6.5Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain ...
CVE-2020-4908MEDIUM5.3IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release in...
CVE-2020-4907MEDIUM5.3IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow a remote attacker to obtain se...
CVE-2020-4905MEDIUM5.9IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an remote attacker to obtain s...
CVE-2020-4904MEDIUM6.5IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forger...
CVE-2020-4658MEDIUM6.1IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2020-4657MEDIUM6.1IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnera...
CVE-2020-28930MEDIUM5.4A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON...
CVE-2020-5359MEDIUM5.8Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An una...
CVE-2020-26198MEDIUM6.1Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in th...
CVE-2020-14248MEDIUM5.3BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause ...
CVE-2020-29362MEDIUM5.3An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC ...
CVE-2020-25619MEDIUM4.4An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channe...
CVE-2020-26273MEDIUM5.2osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before versio...
CVE-2020-26259MEDIUM6.8XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to...
CVE-2020-35416MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admi...
CVE-2020-23957MEDIUM6.1Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by...
CVE-2020-14302MEDIUM4.9A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirec...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now