2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10560 | MEDIUM | 5.9 | 3.8% | Mar 30, 2020 | An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak crypto... |
| CVE-2020-10955 | MEDIUM | 6.5 | 1.0% | Mar 27, 2020 | GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized use... |
| CVE-2020-10952 | MEDIUM | 6.5 | 0.7% | Mar 27, 2020 | GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images. |
| CVE-2020-8552 | MEDIUM | 4.3 | 2.4% | Mar 27, 2020 | The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be v... |
| CVE-2020-8551 | MEDIUM | 6.5 | 1.1% | Mar 27, 2020 | The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a d... |
| CVE-2020-7918 | MEDIUM | 5.4 | 0.7% | Mar 27, 2020 | An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read an... |
| CVE-2020-1771 | MEDIUM | 5.4 | 0.8% | Mar 27, 2020 | Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When age... |
| CVE-2020-1770 | MEDIUM | 4.3 | 1.3% | Mar 27, 2020 | Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue af... |
| CVE-2020-1769 | MEDIUM | 4.3 | 1.3% | Mar 27, 2020 | In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be co... |
| CVE-2020-10510 | MEDIUM | 6.5 | 1.1% | Mar 27, 2020 | Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. Afte... |
| CVE-2020-10509 | MEDIUM | 6.1 | 0.8% | Mar 27, 2020 | Sunnet eHRD, a human training and development management system, contains vulnerability of Cross-Site Scripting (XSS), a... |
| CVE-2020-9468 | MEDIUM | 4.3 | 0.6% | Mar 26, 2020 | The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do n... |
| CVE-2020-9467 | MEDIUM | 5.4 | 23.8% | Mar 26, 2020 | Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function. |
| CVE-2020-9065 | MEDIUM | 5.5 | 0.2% | Mar 26, 2020 | Huawei smart phone Taurus-AL00B with versions earlier than 10.0.0.203(C00E201R7P2) have a use-after-free (UAF) vulnerabi... |
| CVE-2020-6999 | MEDIUM | 6.5 | 1.0% | Mar 26, 2020 | In Moxa EDS-G516E Series firmware, Version 5.2 or lower, some of the parameters in the setting pages do not ensure text ... |
| CVE-2020-5340 | MEDIUM | 4.8 | 0.7% | Mar 26, 2020 | RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security... |
| CVE-2020-5339 | MEDIUM | 4.8 | 0.7% | Mar 26, 2020 | RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security... |
| CVE-2020-8923 | MEDIUM | 6.1 | 0.3% | Mar 26, 2020 | An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an atta... |
| CVE-2020-8910 | MEDIUM | 6.5 | 0.5% | Mar 26, 2020 | A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker ... |
| CVE-2020-10966 | MEDIUM | 6.5 | 1.9% | Mar 25, 2020 | In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header ... |
| CVE-2020-6813 | MEDIUM | 5.3 | 1.2% | Mar 25, 2020 | When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block cou... |
| CVE-2020-6812 | MEDIUM | 5.3 | 1.6% | Mar 25, 2020 | The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's A... |
| CVE-2020-6810 | MEDIUM | 4.3 | 1.0% | Mar 25, 2020 | After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification th... |
| CVE-2020-6808 | MEDIUM | 6.5 | 1.0% | Mar 25, 2020 | When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML doc... |
| CVE-2020-9520 | MEDIUM | 5.4 | 0.8% | Mar 25, 2020 | A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerabil... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now