2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-9416MEDIUM5.4The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS...
CVE-2020-14331MEDIUM6.6A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker att...
CVE-2020-10759MEDIUM6A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware...
CVE-2020-25071MEDIUM5.4Nifty Project Management Web Application 2020-08-26 allows XSS, via Add Task, that is rendered upon a Project Home visit...
CVE-2020-8346MEDIUM5.5A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation...
CVE-2020-8340MEDIUM6.1A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Managem...
CVE-2020-8339MEDIUM6.1A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Mod...
CVE-2020-4711MEDIUM6.5IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to traverse directories on the system. An ...
CVE-2020-4530MEDIUM5.4IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site s...
CVE-2020-4526MEDIUM4.3IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site request forgery which could allow an attacker to...
CVE-2020-16099MEDIUM4.3In Gallagher Command Centre v8.20 prior to v8.20.1093(MR2) it is possible to create Guard Tour events that when accessed...
CVE-2020-16097MEDIUM4.6On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8....
CVE-2020-24924MEDIUM5.4A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user ses...
CVE-2020-13307MEDIUM4.7A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current use...
CVE-2020-13303MEDIUM6.5A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of per...
CVE-2020-8927MEDIUM6.5A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of...
CVE-2020-13310MEDIUM6.5A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the g...
CVE-2020-13305MEDIUM4.3A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not invalidating project...
CVE-2020-13301MEDIUM4.8A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored X...
CVE-2020-13298MEDIUM5.8A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality ...
CVE-2020-13297MEDIUM5.4A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. When 2 factor authentication was en...
CVE-2020-13317MEDIUM4.9A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the Graph...
CVE-2020-13314MEDIUM5.3A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Omniauth endpoint allowed a ...
CVE-2020-13313MEDIUM4.3A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer ...
CVE-2020-13311MEDIUM4.3A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser att...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now