2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10091 | MEDIUM | 6.1 | 0.7% | Mar 13, 2020 | GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types. |
| CVE-2020-10090 | MEDIUM | 5.3 | 0.9% | Mar 13, 2020 | GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was uni... |
| CVE-2020-10086 | MEDIUM | 5.3 | 1.3% | Mar 13, 2020 | GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vul... |
| CVE-2020-10085 | MEDIUM | 5.3 | 0.9% | Mar 13, 2020 | GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request t... |
| CVE-2020-10084 | MEDIUM | 5.3 | 0.9% | Mar 13, 2020 | GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_fe... |
| CVE-2020-10082 | MEDIUM | 5.3 | 1.1% | Mar 13, 2020 | GitLab 12.2 through 12.8.1 allows Denial of Service. A denial of service vulnerability impacting the designs for public ... |
| CVE-2020-10081 | MEDIUM | 6.5 | 0.9% | Mar 13, 2020 | GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potent... |
| CVE-2020-10080 | MEDIUM | 5.3 | 0.9% | Mar 13, 2020 | GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribut... |
| CVE-2020-10079 | MEDIUM | 5.3 | 0.9% | Mar 13, 2020 | GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required ... |
| CVE-2020-10078 | MEDIUM | 6.1 | 0.7% | Mar 13, 2020 | GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scri... |
| CVE-2020-10196 | MEDIUM | 6.1 | 1.4% | Mar 13, 2020 | An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary... |
| CVE-2020-10195 | MEDIUM | 6.3 | 1.1% | Mar 13, 2020 | The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to... |
| CVE-2020-10544 | MEDIUM | 6.1 | 0.8% | Mar 13, 2020 | An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, ... |
| CVE-2020-7600 | MEDIUM | 5.3 | 1.1% | Mar 12, 2020 | querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name... |
| CVE-2020-10535 | MEDIUM | 5.3 | 1.0% | Mar 12, 2020 | GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within... |
| CVE-2020-9064 | MEDIUM | 5.5 | 0.2% | Mar 12, 2020 | Huawei smartphone Honor V30 with versions earlier than OxfordS-AN00A 10.0.1.167(C00E166R4P1) have an improper authentica... |
| CVE-2020-6643 | MEDIUM | 5.4 | 0.8% | Mar 12, 2020 | An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows ... |
| CVE-2020-0551 | MEDIUM | 5.6 | 1.0% | Mar 12, 2020 | Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to pote... |
| CVE-2020-0550 | MEDIUM | 5.6 | 0.3% | Mar 12, 2020 | Improper data forwarding in some data cache for some Intel(R) Processors may allow an authenticated user to potentially ... |
| CVE-2020-0574 | MEDIUM | 5.9 | 0.4% | Mar 12, 2020 | Improper configuration in block design for Intel(R) MAX(R) 10 FPGA all versions may allow an authenticated user to poten... |
| CVE-2020-0567 | MEDIUM | 5.5 | 0.3% | Mar 12, 2020 | Improper input validation in Intel(R) Graphics Drivers before version 26.20.100.7212 may allow an authenticated user to ... |
| CVE-2020-0526 | MEDIUM | 6.7 | 0.3% | Mar 12, 2020 | Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of p... |
| CVE-2020-5961 | MEDIUM | 5.5 | 0.3% | Mar 12, 2020 | NVIDIA vGPU graphics driver for guest OS contains a vulnerability in which an incorrect resource clean up on a failure p... |
| CVE-2020-5960 | MEDIUM | 5.5 | 0.3% | Mar 12, 2020 | NVIDIA Virtual GPU Manager contains a vulnerability in the kernel module (nvidia.ko), where a null pointer dereference m... |
| CVE-2020-5959 | MEDIUM | 5.5 | 0.3% | Mar 12, 2020 | NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in the vGPU plugin in which an input index value is i... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now