2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-5855MEDIUM4.3When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorize...
CVE-2020-5854MEDIUM5.9On BIG-IP 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.0-11.6.5.1, the tmm ...
CVE-2020-5528MEDIUM6.1Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4603 and earlier (Movable Type 7), Movable T...
CVE-2020-8649MEDIUM5.9There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in driver...
CVE-2020-8647MEDIUM6.1There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt...
CVE-2020-6854MEDIUM5.4A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attac...
CVE-2020-3149MEDIUM4.8A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an au...
CVE-2020-3120MEDIUM6.5A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco...
CVE-2020-8506MEDIUM5.3The Global TV application 2.3.2 for Android and 4.7.5 for iOS sends Unencrypted Analytics.
CVE-2020-7977MEDIUM5.3GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.
CVE-2020-7976MEDIUM5.3GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.
CVE-2020-7974MEDIUM5.3GitLab EE 10.1 through 12.7.2 allows Information Disclosure.
CVE-2020-7973MEDIUM6.1GitLab through 12.7.2 allows XSS.
CVE-2020-7971MEDIUM6.1GitLab EE 11.0 and later through 12.7.2 allows XSS.
CVE-2020-7967MEDIUM4.3GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).
CVE-2020-7979MEDIUM5.3GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
CVE-2020-8632MEDIUM5.5In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, ...
CVE-2020-8631MEDIUM5.5cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict...
CVE-2020-8615MEDIUM6.5A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves a...
CVE-2020-8124MEDIUM5.3Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may all...
CVE-2020-8123MEDIUM4.9A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin ri...
CVE-2020-8122MEDIUM4.3A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share...
CVE-2020-8120MEDIUM6.1A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.
CVE-2020-8119MEDIUM4.3Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is op...
CVE-2020-8118MEDIUM5An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now