2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15237 | MEDIUM | 5.9 | 1.0% | Oct 5, 2020 | In Shrine before version 3.3.0, when using the `derivation_endpoint` plugin, it's possible for the attacker to use a tim... |
| CVE-2020-8671 | MEDIUM | 5.5 | 0.3% | Oct 5, 2020 | Insufficient control flow management in BIOS firmware 8th, 9th Generation Intel(R) Core(TM) Processors and Intel(R) Cele... |
| CVE-2020-8235 | MEDIUM | 4.3 | 0.8% | Oct 5, 2020 | Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view a... |
| CVE-2020-8228 | MEDIUM | 5.3 | 1.9% | Oct 5, 2020 | A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount... |
| CVE-2020-8223 | MEDIUM | 6.5 | 1.5% | Oct 5, 2020 | A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher p... |
| CVE-2020-25635 | MEDIUM | 5.5 | 0.3% | Oct 5, 2020 | A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after pl... |
| CVE-2020-0571 | MEDIUM | 5.5 | 0.3% | Oct 5, 2020 | Improper conditions check in BIOS firmware for 8th Generation Intel(R) Core(TM) Processors and Intel(R) Pentium(R) Silve... |
| CVE-2020-26166 | MEDIUM | 5.4 | 0.8% | Oct 5, 2020 | The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attacker... |
| CVE-2020-5989 | MEDIUM | 5.5 | 0.3% | Oct 2, 2020 | NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it can dereference a NULL pointer, whic... |
| CVE-2020-5986 | MEDIUM | 5.5 | 0.3% | Oct 2, 2020 | NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, wh... |
| CVE-2020-15234 | MEDIUM | 4.8 | 0.8% | Oct 2, 2020 | ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite before version 0.34.1, the OAuth 2.0 ... |
| CVE-2020-15233 | MEDIUM | 4.8 | 0.8% | Oct 2, 2020 | ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite from version 0.30.2 and before versio... |
| CVE-2020-26526 | MEDIUM | 5.3 | 1.4% | Oct 2, 2020 | An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. Th... |
| CVE-2020-15231 | MEDIUM | 6.1 | 0.8% | Oct 2, 2020 | In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting. |
| CVE-2020-13338 | MEDIUM | 5.4 | 0.7% | Oct 2, 2020 | An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripti... |
| CVE-2020-13337 | MEDIUM | 4.8 | 0.7% | Oct 2, 2020 | An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload t... |
| CVE-2020-5982 | MEDIUM | 4.4 | 0.3% | Oct 2, 2020 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) schedu... |
| CVE-2020-26541 | MEDIUM | 6.5 | 0.5% | Oct 2, 2020 | The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protect... |
| CVE-2020-24627 | MEDIUM | 5.4 | 0.5% | Oct 2, 2020 | A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3. |
| CVE-2020-24568 | MEDIUM | 6.5 | 0.8% | Oct 2, 2020 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection i... |
| CVE-2020-15230 | MEDIUM | 6.5 | 1.5% | Oct 2, 2020 | Vapor is a web framework for Swift. In Vapor before version 4.29.4, Attackers can access data at arbitrary filesystem pa... |
| CVE-2020-5422 | MEDIUM | 6.5 | 0.9% | Oct 2, 2020 | BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH d... |
| CVE-2020-7070 | MEDIUM | 5.3 | 5.0% | Oct 2, 2020 | In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cook... |
| CVE-2020-7069 | MEDIUM | 6.5 | 2.0% | Oct 2, 2020 | In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_en... |
| CVE-2020-26135 | MEDIUM | 6.1 | 1.0% | Oct 2, 2020 | Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now