2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-10091MEDIUM6.1GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.
CVE-2020-10090MEDIUM5.3GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was uni...
CVE-2020-10086MEDIUM5.3GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vul...
CVE-2020-10085MEDIUM5.3GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request t...
CVE-2020-10084MEDIUM5.3GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_fe...
CVE-2020-10082MEDIUM5.3GitLab 12.2 through 12.8.1 allows Denial of Service. A denial of service vulnerability impacting the designs for public ...
CVE-2020-10081MEDIUM6.5GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potent...
CVE-2020-10080MEDIUM5.3GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribut...
CVE-2020-10079MEDIUM5.3GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required ...
CVE-2020-10078MEDIUM6.1GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scri...
CVE-2020-10196MEDIUM6.1An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary...
CVE-2020-10195MEDIUM6.3The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to...
CVE-2020-10544MEDIUM6.1An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, ...
CVE-2020-7600MEDIUM5.3querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name...
CVE-2020-10535MEDIUM5.3GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within...
CVE-2020-9064MEDIUM5.5Huawei smartphone Honor V30 with versions earlier than OxfordS-AN00A 10.0.1.167(C00E166R4P1) have an improper authentica...
CVE-2020-6643MEDIUM5.4An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows ...
CVE-2020-0551MEDIUM5.6Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to pote...
CVE-2020-0550MEDIUM5.6Improper data forwarding in some data cache for some Intel(R) Processors may allow an authenticated user to potentially ...
CVE-2020-0574MEDIUM5.9Improper configuration in block design for Intel(R) MAX(R) 10 FPGA all versions may allow an authenticated user to poten...
CVE-2020-0567MEDIUM5.5Improper input validation in Intel(R) Graphics Drivers before version 26.20.100.7212 may allow an authenticated user to ...
CVE-2020-0526MEDIUM6.7Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of p...
CVE-2020-5961MEDIUM5.5NVIDIA vGPU graphics driver for guest OS contains a vulnerability in which an incorrect resource clean up on a failure p...
CVE-2020-5960MEDIUM5.5NVIDIA Virtual GPU Manager contains a vulnerability in the kernel module (nvidia.ko), where a null pointer dereference m...
CVE-2020-5959MEDIUM5.5NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in the vGPU plugin in which an input index value is i...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now