2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-10889HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0...
CVE-2020-11506HIGH7.5An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads...
CVE-2020-11505HIGH7.5An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9...
CVE-2020-7490HIGH7.8A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Desig...
CVE-2020-7488HIGH7.5A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information t...
CVE-2020-12066HIGH7.5CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the se...
CVE-2020-11011HIGH8.8In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arb...
CVE-2020-5740HIGH7.8Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary ...
CVE-2020-10712HIGH8.2A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by ...
CVE-2020-8477HIGH8.8The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxil...
CVE-2020-8474HIGH7.8Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings relat...
CVE-2020-11795HIGH7.5In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
CVE-2020-11693HIGH7.5JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an...
CVE-2020-11691HIGH7.5In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.
CVE-2020-11688HIGH7.5In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
CVE-2020-11687HIGH7.5In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
CVE-2020-11685HIGH7.5In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.
CVE-2020-11539HIGH8.1An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pai...
CVE-2020-12059HIGH7.5An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by ...
CVE-2020-12051HIGH7.5The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account infor...
CVE-2020-11008HIGH7.5Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host cont...
CVE-2020-8895HIGH7.8Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attac...
CVE-2020-5268HIGH7.3In Saml2 Authentication Services for ASP.NET versions before 1.0.2, and between 2.0.0 and 2.6.0, there is a vulnerabilit...
CVE-2020-1757HIGH8.1A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x ...
CVE-2020-1699HIGH7.5A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now