2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28915 | MEDIUM | 5.8 | 0.4% | Nov 18, 2020 | A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local... |
| CVE-2020-28092 | MEDIUM | 6.1 | 2.2% | Nov 17, 2020 | PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&s... |
| CVE-2020-28129 | MEDIUM | 6.1 | 0.9% | Nov 17, 2020 | Stored Cross-site scripting (XSS) vulnerability in SourceCodester Gym Management System 1.0 allows users to inject and s... |
| CVE-2020-26216 | MEDIUM | 6.1 | 1.0% | Nov 17, 2020 | TYPO3 Fluid before versions 2.0.8, 2.1.7, 2.2.4, 2.3.7, 2.4.4, 2.5.11 and 2.6.10 is vulnerable to Cross-Site Scripting. ... |
| CVE-2020-25890 | MEDIUM | 6.1 | 1.5% | Nov 17, 2020 | The web application of Kyocera printer (ECOSYS M2640IDW) is affected by Stored XSS vulnerability, discovered in the addi... |
| CVE-2020-25988 | MEDIUM | 6.5 | 3.0% | Nov 17, 2020 | UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' wh... |
| CVE-2020-28139 | MEDIUM | 6.1 | 0.8% | Nov 17, 2020 | SourceCodester Online Clothing Store 1.0 is affected by a cross-site scripting (XSS) vulnerability via a Offer Detail fi... |
| CVE-2020-13349 | MEDIUM | 4.3 | 0.9% | Nov 17, 2020 | An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a f... |
| CVE-2020-13348 | MEDIUM | 5.7 | 0.8% | Nov 17, 2020 | An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could ... |
| CVE-2020-26701 | MEDIUM | 5.4 | 0.9% | Nov 17, 2020 | Cross-site scripting (XSS) vulnerability in Dashboards section in Kaa IoT Platform v1.2.0 allows remote attackers to inj... |
| CVE-2020-13351 | MEDIUM | 6.5 | 1.3% | Nov 17, 2020 | Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names... |
| CVE-2020-13350 | MEDIUM | 4.3 | 0.7% | Nov 17, 2020 | CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instan... |
| CVE-2020-27558 | MEDIUM | 6.5 | 1.1% | Nov 17, 2020 | Use of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video st... |
| CVE-2020-27557 | MEDIUM | 5.5 | 0.3% | Nov 17, 2020 | Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to g... |
| CVE-2020-27556 | MEDIUM | 5.3 | 1.0% | Nov 17, 2020 | A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to conne... |
| CVE-2020-25798 | MEDIUM | 5.4 | 0.6% | Nov 17, 2020 | A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users w... |
| CVE-2020-28647 | MEDIUM | 5.4 | 1.4% | Nov 17, 2020 | In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a... |
| CVE-2020-25746 | MEDIUM | 4.6 | 0.3% | Nov 17, 2020 | QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obta... |
| CVE-2020-25833 | MEDIUM | 4.8 | 0.5% | Nov 17, 2020 | Persistent cross-Site Scripting vulnerability on Micro Focus IDOL product, affecting all version prior to version 12.7. ... |
| CVE-2020-25832 | MEDIUM | 5.4 | 0.5% | Nov 17, 2020 | Reflected Cross Site scripting vulnerability on Micro Focus Filr product, affecting version 4.2.1. The vulnerability cou... |
| CVE-2020-10776 | MEDIUM | 4.8 | 0.8% | Nov 17, 2020 | A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri para... |
| CVE-2020-26406 | MEDIUM | 5.3 | 1.4% | Nov 17, 2020 | Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This inf... |
| CVE-2020-25834 | MEDIUM | 5.4 | 0.7% | Nov 17, 2020 | Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability coul... |
| CVE-2020-13358 | MEDIUM | 5.5 | 0.3% | Nov 17, 2020 | A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access t... |
| CVE-2020-13354 | MEDIUM | 4.3 | 1.4% | Nov 17, 2020 | A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name che... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now