2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26417 | MEDIUM | 5.3 | 1.2% | Dec 11, 2020 | Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This aff... |
| CVE-2020-26416 | MEDIUM | 4.4 | 0.3% | Dec 11, 2020 | Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms v... |
| CVE-2020-26415 | MEDIUM | 4.3 | 0.8% | Dec 11, 2020 | Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via ... |
| CVE-2020-26413 | MEDIUM | 5.3 | 33.8% | Dec 11, 2020 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclo... |
| CVE-2020-26412 | MEDIUM | 4.3 | 1.0% | Dec 11, 2020 | Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics sta... |
| CVE-2020-26408 | MEDIUM | 5.3 | 1.0% | Dec 11, 2020 | A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=... |
| CVE-2020-13357 | MEDIUM | 4.3 | 0.8% | Dec 11, 2020 | An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed ... |
| CVE-2020-26409 | MEDIUM | 6.5 | 1.2% | Dec 11, 2020 | A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to tr... |
| CVE-2020-25838 | MEDIUM | 6.5 | 0.8% | Dec 11, 2020 | Unauthorized disclosure of sensitive information vulnerability in Micro Focus Filr product. Affecting all 3.x and 4.x ve... |
| CVE-2020-7549 | MEDIUM | 5.3 | 1.0% | Dec 11, 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, ... |
| CVE-2020-7541 | MEDIUM | 5.3 | 0.9% | Dec 11, 2020 | A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modi... |
| CVE-2020-28220 | MEDIUM | 6.8 | 1.0% | Dec 11, 2020 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 ... |
| CVE-2020-28218 | MEDIUM | 6.5 | 1.1% | Dec 11, 2020 | A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and ... |
| CVE-2020-28214 | MEDIUM | 5.5 | 0.7% | Dec 11, 2020 | A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versi... |
| CVE-2020-26268 | MEDIUM | 4.4 | 0.2% | Dec 10, 2020 | In affected versions of TensorFlow the tf.raw_ops.ImmutableConst operation returns a constant tensor created from a memo... |
| CVE-2020-26266 | MEDIUM | 5.3 | 0.2% | Dec 10, 2020 | In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code... |
| CVE-2020-29666 | MEDIUM | 5.3 | 1.4% | Dec 10, 2020 | In Lan ATMService M3 ATM Monitoring System 6.1.0, due to a directory-listing vulnerability, a remote attacker can view l... |
| CVE-2020-26407 | MEDIUM | 5.4 | 0.7% | Dec 10, 2020 | A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allo... |
| CVE-2020-24444 | MEDIUM | 5.8 | 2.1% | Dec 10, 2020 | AEM Forms SP6 add-on for AEM 6.5.6.0 and Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2)... |
| CVE-2020-12595 | MEDIUM | 4.9 | 0.9% | Dec 10, 2020 | An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remo... |
| CVE-2020-2498 | MEDIUM | 6.1 | 0.6% | Dec 10, 2020 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certifica... |
| CVE-2020-2497 | MEDIUM | 6.1 | 1.0% | Dec 10, 2020 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Co... |
| CVE-2020-2496 | MEDIUM | 6.1 | 1.0% | Dec 10, 2020 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Stat... |
| CVE-2020-2495 | MEDIUM | 6.1 | 1.0% | Dec 10, 2020 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Stat... |
| CVE-2020-2494 | MEDIUM | 6.1 | 1.0% | Dec 10, 2020 | This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have alr... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now