2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-10227MEDIUM6.1A cross-site scripting (XSS) vulnerability in the messages module of vtecrm vtenext 19 CE allows attackers to inject arb...
CVE-2020-13316MEDIUM4.3A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-...
CVE-2020-13289MEDIUM5.4A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid usernam...
CVE-2020-13287MEDIUM4.3A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could s...
CVE-2020-13284MEDIUM6.5A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI...
CVE-2020-21845MEDIUM6.1Codoforum 4.8.3 allows HTML Injection in the 'admin dashboard Manage users Section.'
CVE-2020-25380MEDIUM5.4Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 is affected by: Cross Site Scripting (XSS) via the 'Recal...
CVE-2020-25378MEDIUM6.1Wordpress Plugin Store / AccessPress Themes WP Floating Menu V1.3.0 is affected by: Cross Site Scripting (XSS) via the i...
CVE-2020-25375MEDIUM5.4Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name ...
CVE-2020-22158MEDIUM6.1MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has...
CVE-2020-11683MEDIUM6.8A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical acces...
CVE-2020-7807MEDIUM5.5A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTR...
CVE-2020-21733MEDIUM6.1Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.
CVE-2020-21732MEDIUM6.1Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code t...
CVE-2020-21731MEDIUM6.1Gazie 7.29 is affected by: Cross Site Scripting (XSS) via http://192.168.100.7/gazie/modules/config/admin_utente.php?use...
CVE-2020-25289MEDIUM5.5The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Man...
CVE-2020-25286MEDIUM5.3In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in t...
CVE-2020-25285MEDIUM6.4A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local...
CVE-2020-25284MEDIUM4.1The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking...
CVE-2020-25280MEDIUM6.8An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos and MediaTek chipsets) software. Unauthenticated ...
CVE-2020-14332MEDIUM5.5A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not prop...
CVE-2020-14330MEDIUM5.5An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is ...
CVE-2020-1598MEDIUM6.1<p>An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly han...
CVE-2020-1596MEDIUM5.4<p>A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfu...
CVE-2020-1592MEDIUM4.4<p>An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.</p> ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now