2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-28915MEDIUM5.8A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local...
CVE-2020-28092MEDIUM6.1PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&s...
CVE-2020-28129MEDIUM6.1Stored Cross-site scripting (XSS) vulnerability in SourceCodester Gym Management System 1.0 allows users to inject and s...
CVE-2020-26216MEDIUM6.1TYPO3 Fluid before versions 2.0.8, 2.1.7, 2.2.4, 2.3.7, 2.4.4, 2.5.11 and 2.6.10 is vulnerable to Cross-Site Scripting. ...
CVE-2020-25890MEDIUM6.1The web application of Kyocera printer (ECOSYS M2640IDW) is affected by Stored XSS vulnerability, discovered in the addi...
CVE-2020-25988MEDIUM6.5UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' wh...
CVE-2020-28139MEDIUM6.1SourceCodester Online Clothing Store 1.0 is affected by a cross-site scripting (XSS) vulnerability via a Offer Detail fi...
CVE-2020-13349MEDIUM4.3An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a f...
CVE-2020-13348MEDIUM5.7An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could ...
CVE-2020-26701MEDIUM5.4Cross-site scripting (XSS) vulnerability in Dashboards section in Kaa IoT Platform v1.2.0 allows remote attackers to inj...
CVE-2020-13351MEDIUM6.5Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names...
CVE-2020-13350MEDIUM4.3CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instan...
CVE-2020-27558MEDIUM6.5Use of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video st...
CVE-2020-27557MEDIUM5.5Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to g...
CVE-2020-27556MEDIUM5.3A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to conne...
CVE-2020-25798MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users w...
CVE-2020-28647MEDIUM5.4In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a...
CVE-2020-25746MEDIUM4.6QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obta...
CVE-2020-25833MEDIUM4.8Persistent cross-Site Scripting vulnerability on Micro Focus IDOL product, affecting all version prior to version 12.7. ...
CVE-2020-25832MEDIUM5.4Reflected Cross Site scripting vulnerability on Micro Focus Filr product, affecting version 4.2.1. The vulnerability cou...
CVE-2020-10776MEDIUM4.8A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri para...
CVE-2020-26406MEDIUM5.3Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This inf...
CVE-2020-25834MEDIUM5.4Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability coul...
CVE-2020-13358MEDIUM5.5A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access t...
CVE-2020-13354MEDIUM4.3A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name che...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now