2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-10587HIGH7.8antiX and MX Linux allow local users to achieve root access via "persist-config --command /bin/sh" because of the Sudo c...
CVE-2020-10578HIGH7.5An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1.
CVE-2020-10573HIGH7.5An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms...
CVE-2020-10568HIGH8.8The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This lea...
CVE-2020-10566HIGH7.8grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, mishandles font loading by a guest through a gr...
CVE-2020-10565HIGH7.8grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, does not validate the address provided as part ...
CVE-2020-5240HIGH8.5In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the...
CVE-2020-5257HIGH8.1In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard, the direction parameter was ...
CVE-2020-10562HIGH7.2An issue was discovered in DEVOME GRR before 3.4.1c. admin_edit_room.php mishandles file uploads.
CVE-2020-10073HIGH7.5GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of servic...
CVE-2020-10089HIGH7.5GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,
CVE-2020-10088HIGH8.1GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited...
CVE-2020-10087HIGH7.5GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings ...
CVE-2020-8571HIGH7.5StorageGRID (formerly StorageGRID Webscale) versions 10.0.0 through 11.3 prior to 11.2.0.8 and 11.3.0.4 are susceptible ...
CVE-2020-10540HIGH8.8Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.
CVE-2020-8469HIGH7.8Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentiall...
CVE-2020-1863HIGH7.5Huawei USG6000V with versions V500R001C20SPC300, V500R003C00SPC100, and V500R005C00SPC100 have an out-of-bounds read vul...
CVE-2020-0583HIGH8.8Improper access control in the subsystem for Intel(R) Smart Sound Technology may allow an authenticated user to potentia...
CVE-2020-0565HIGH7.8Uncontrolled search path in Intel(R) Graphics Drivers before version 26.20.100.7158 may allow an authenticated user to p...
CVE-2020-0556HIGH7.1Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enab...
CVE-2020-0546HIGH7.8Unquoted service path in Intel(R) Optane(TM) DC Persistent Memory Module Management Software before version 1.0.0.3461 m...
CVE-2020-0530HIGH7.8Improper buffer restrictions in firmware for Intel(R) NUC may allow an authenticated user to potentially enable escalati...
CVE-2020-0520HIGH7.8Path traversal in igdkmd64.sys for Intel(R) Graphics Drivers before versions 15.45.30.5103, 15.40.44.5107, 15.36.38.5117...
CVE-2020-0519HIGH7.8Improper access control for Intel(R) Graphics Drivers before versions 15.33.49.5100 and 15.36.38.5117 may allow an authe...
CVE-2020-0515HIGH7.8Uncontrolled search path element in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7584, 15.45.30...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now