2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-13315HIGH7.5A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not r...
CVE-2020-13309HIGH8.8A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SS...
CVE-2020-13306HIGH7.5A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abu...
CVE-2020-13304HIGH7.2A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret...
CVE-2020-13302HIGH7.2A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was...
CVE-2020-11881HIGH7.5An array index error in MikroTik RouterOS 6.41.3 through 6.46.5, and 7.x through 7.0 Beta5, allows an unauthenticated re...
CVE-2020-10229HIGH8.8A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such a...
CVE-2020-10228HIGH8.8A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, re...
CVE-2020-25574HIGH7.5An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() could resu...
CVE-2020-24457HIGH7.6Logic error in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processors may allow an unauthenticated ...
CVE-2020-13318HIGH7.3A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration wa...
CVE-2020-13299HIGH8.1A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revo...
CVE-2020-0570HIGH7.3Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potential...
CVE-2020-25379HIGH8.8Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' paramet...
CVE-2020-8817HIGH8.1Dataiku DSS before 6.0.5 allows attackers write access to the project to modify the "Created by" metadata.
CVE-2020-12789HIGH7.5The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.
CVE-2020-12788HIGH7.5CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power anal...
CVE-2020-12787HIGH7.5Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to appl...
CVE-2020-25540HIGH7.5ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on ...
CVE-2020-25291HIGH7.8GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in ...
CVE-2020-25287HIGH7.2Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any fil...
CVE-2020-25281HIGH7.5An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Applications with sen...
CVE-2020-23824HIGH8.8ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code executi...
CVE-2020-14363HIGH7.8An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged atta...
CVE-2020-1594HIGH7.8<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle o...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now