2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10227 | MEDIUM | 6.1 | 1.1% | Sep 14, 2020 | A cross-site scripting (XSS) vulnerability in the messages module of vtecrm vtenext 19 CE allows attackers to inject arb... |
| CVE-2020-13316 | MEDIUM | 4.3 | 1.4% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-... |
| CVE-2020-13289 | MEDIUM | 5.4 | 0.7% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid usernam... |
| CVE-2020-13287 | MEDIUM | 4.3 | 1.2% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could s... |
| CVE-2020-13284 | MEDIUM | 6.5 | 1.1% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI... |
| CVE-2020-21845 | MEDIUM | 6.1 | 0.8% | Sep 14, 2020 | Codoforum 4.8.3 allows HTML Injection in the 'admin dashboard Manage users Section.' |
| CVE-2020-25380 | MEDIUM | 5.4 | 0.7% | Sep 14, 2020 | Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 is affected by: Cross Site Scripting (XSS) via the 'Recal... |
| CVE-2020-25378 | MEDIUM | 6.1 | 0.9% | Sep 14, 2020 | Wordpress Plugin Store / AccessPress Themes WP Floating Menu V1.3.0 is affected by: Cross Site Scripting (XSS) via the i... |
| CVE-2020-25375 | MEDIUM | 5.4 | 0.7% | Sep 14, 2020 | Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name ... |
| CVE-2020-22158 | MEDIUM | 6.1 | 0.7% | Sep 14, 2020 | MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has... |
| CVE-2020-11683 | MEDIUM | 6.8 | 0.5% | Sep 14, 2020 | A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical acces... |
| CVE-2020-7807 | MEDIUM | 5.5 | 0.2% | Sep 14, 2020 | A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTR... |
| CVE-2020-21733 | MEDIUM | 6.1 | 1.0% | Sep 14, 2020 | Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp. |
| CVE-2020-21732 | MEDIUM | 6.1 | 0.9% | Sep 14, 2020 | Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code t... |
| CVE-2020-21731 | MEDIUM | 6.1 | 0.9% | Sep 14, 2020 | Gazie 7.29 is affected by: Cross Site Scripting (XSS) via http://192.168.100.7/gazie/modules/config/admin_utente.php?use... |
| CVE-2020-25289 | MEDIUM | 5.5 | 0.4% | Sep 13, 2020 | The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Man... |
| CVE-2020-25286 | MEDIUM | 5.3 | 1.9% | Sep 13, 2020 | In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in t... |
| CVE-2020-25285 | MEDIUM | 6.4 | 0.3% | Sep 13, 2020 | A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local... |
| CVE-2020-25284 | MEDIUM | 4.1 | 0.3% | Sep 13, 2020 | The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking... |
| CVE-2020-25280 | MEDIUM | 6.8 | 0.2% | Sep 11, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos and MediaTek chipsets) software. Unauthenticated ... |
| CVE-2020-14332 | MEDIUM | 5.5 | 0.4% | Sep 11, 2020 | A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not prop... |
| CVE-2020-14330 | MEDIUM | 5.5 | 0.6% | Sep 11, 2020 | An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is ... |
| CVE-2020-1598 | MEDIUM | 6.1 | 0.9% | Sep 11, 2020 | <p>An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly han... |
| CVE-2020-1596 | MEDIUM | 5.4 | 0.9% | Sep 11, 2020 | <p>A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfu... |
| CVE-2020-1592 | MEDIUM | 4.4 | 1.2% | Sep 11, 2020 | <p>An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.</p> ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now