2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-15237MEDIUM5.9In Shrine before version 3.3.0, when using the `derivation_endpoint` plugin, it's possible for the attacker to use a tim...
CVE-2020-8671MEDIUM5.5Insufficient control flow management in BIOS firmware 8th, 9th Generation Intel(R) Core(TM) Processors and Intel(R) Cele...
CVE-2020-8235MEDIUM4.3Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view a...
CVE-2020-8228MEDIUM5.3A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount...
CVE-2020-8223MEDIUM6.5A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher p...
CVE-2020-25635MEDIUM5.5A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after pl...
CVE-2020-0571MEDIUM5.5Improper conditions check in BIOS firmware for 8th Generation Intel(R) Core(TM) Processors and Intel(R) Pentium(R) Silve...
CVE-2020-26166MEDIUM5.4The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attacker...
CVE-2020-5989MEDIUM5.5NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it can dereference a NULL pointer, whic...
CVE-2020-5986MEDIUM5.5NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, wh...
CVE-2020-15234MEDIUM4.8ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite before version 0.34.1, the OAuth 2.0 ...
CVE-2020-15233MEDIUM4.8ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite from version 0.30.2 and before versio...
CVE-2020-26526MEDIUM5.3An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. Th...
CVE-2020-15231MEDIUM6.1In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.
CVE-2020-13338MEDIUM5.4An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripti...
CVE-2020-13337MEDIUM4.8An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload t...
CVE-2020-5982MEDIUM4.4NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) schedu...
CVE-2020-26541MEDIUM6.5The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protect...
CVE-2020-24627MEDIUM5.4A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.
CVE-2020-24568MEDIUM6.5An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection i...
CVE-2020-15230MEDIUM6.5Vapor is a web framework for Swift. In Vapor before version 4.29.4, Attackers can access data at arbitrary filesystem pa...
CVE-2020-5422MEDIUM6.5BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH d...
CVE-2020-7070MEDIUM5.3In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cook...
CVE-2020-7069MEDIUM6.5In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_en...
CVE-2020-26135MEDIUM6.1Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now