2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15488 | HIGH | 7.5 | 1.0% | Sep 30, 2020 | Re:Desk 2.3 allows insecure file upload. |
| CVE-2020-14377 | HIGH | 7.1 | 0.4% | Sep 30, 2020 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-contr... |
| CVE-2020-14376 | HIGH | 7.8 | 0.4% | Sep 30, 2020 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data ... |
| CVE-2020-14375 | HIGH | 7.8 | 0.3% | Sep 30, 2020 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they desc... |
| CVE-2020-8243 | HIGH | 7.2 | 90.8% | Sep 30, 2020 | A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to uploa... |
| CVE-2020-26163 | HIGH | 8.8 | 1.5% | Sep 30, 2020 | BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover... |
| CVE-2020-26160 | HIGH | 7.5 | 2.1% | Sep 30, 2020 | jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m... |
| CVE-2020-26150 | HIGH | 7.5 | 1.3% | Sep 30, 2020 | info.php in Logaritmo Aware CallManager 2012 allows remote attackers to obtain sensitive information via a direct reques... |
| CVE-2020-26149 | HIGH | 7.5 | 1.5% | Sep 30, 2020 | NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a... |
| CVE-2020-26148 | HIGH | 7.5 | 1.4% | Sep 30, 2020 | md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial ... |
| CVE-2020-25760 | HIGH | 8.8 | 2.2% | Sep 30, 2020 | Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input valid... |
| CVE-2020-21564 | HIGH | 8.8 | 3.5% | Sep 30, 2020 | An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remot... |
| CVE-2020-21527 | HIGH | 7.7 | 1.1% | Sep 30, 2020 | There is an Arbitrary file deletion vulnerability in halo v1.1.3. A backup function in the background allows a user, whe... |
| CVE-2020-21525 | HIGH | 7.5 | 1.9% | Sep 30, 2020 | Halo V1.1.3 is affected by: Arbitrary File reading. In an interface that reads files in halo v1.1.3, a directory travers... |
| CVE-2020-14030 | HIGH | 7.2 | 1.8% | Sep 30, 2020 | An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the ... |
| CVE-2020-13951 | HIGH | 7.5 | 69.1% | Sep 30, 2020 | Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. |
| CVE-2020-13658 | HIGH | 8 | 0.5% | Sep 30, 2020 | In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to... |
| CVE-2020-13325 | HIGH | 7.1 | 0.9% | Sep 30, 2020 | A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting ... |
| CVE-2020-13323 | HIGH | 7.7 | 1.1% | Sep 30, 2020 | A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be r... |
| CVE-2020-13322 | HIGH | 7.2 | 1.1% | Sep 30, 2020 | A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthoriz... |
| CVE-2020-13321 | HIGH | 8.3 | 1.4% | Sep 30, 2020 | A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing... |
| CVE-2020-13296 | HIGH | 8.8 | 1.6% | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper ... |
| CVE-2020-12505 | HIGH | 8.2 | 1.2% | Sep 30, 2020 | Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some s... |
| CVE-2020-4607 | HIGH | 7.8 | 0.3% | Sep 29, 2020 | IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security... |
| CVE-2020-25773 | HIGH | 7.8 | 2.4% | Sep 29, 2020 | A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary c... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now