2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-15488HIGH7.5Re:Desk 2.3 allows insecure file upload.
CVE-2020-14377HIGH7.1A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-contr...
CVE-2020-14376HIGH7.8A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data ...
CVE-2020-14375HIGH7.8A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they desc...
CVE-2020-8243HIGH7.2A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to uploa...
CVE-2020-26163HIGH8.8BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover...
CVE-2020-26160HIGH7.5jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m...
CVE-2020-26150HIGH7.5info.php in Logaritmo Aware CallManager 2012 allows remote attackers to obtain sensitive information via a direct reques...
CVE-2020-26149HIGH7.5NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a...
CVE-2020-26148HIGH7.5md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial ...
CVE-2020-25760HIGH8.8Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input valid...
CVE-2020-21564HIGH8.8An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remot...
CVE-2020-21527HIGH7.7There is an Arbitrary file deletion vulnerability in halo v1.1.3. A backup function in the background allows a user, whe...
CVE-2020-21525HIGH7.5Halo V1.1.3 is affected by: Arbitrary File reading. In an interface that reads files in halo v1.1.3, a directory travers...
CVE-2020-14030HIGH7.2An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the ...
CVE-2020-13951HIGH7.5Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
CVE-2020-13658HIGH8In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to...
CVE-2020-13325HIGH7.1A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting ...
CVE-2020-13323HIGH7.7A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be r...
CVE-2020-13322HIGH7.2A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthoriz...
CVE-2020-13321HIGH8.3A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing...
CVE-2020-13296HIGH8.8An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper ...
CVE-2020-12505HIGH8.2Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some s...
CVE-2020-4607HIGH7.8IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security...
CVE-2020-25773HIGH7.8A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary c...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now