2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5855 | MEDIUM | 4.3 | 0.3% | Feb 6, 2020 | When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorize... |
| CVE-2020-5854 | MEDIUM | 5.9 | 0.8% | Feb 6, 2020 | On BIG-IP 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.0-11.6.5.1, the tmm ... |
| CVE-2020-5528 | MEDIUM | 6.1 | 0.8% | Feb 6, 2020 | Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4603 and earlier (Movable Type 7), Movable T... |
| CVE-2020-8649 | MEDIUM | 5.9 | 0.5% | Feb 6, 2020 | There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in driver... |
| CVE-2020-8647 | MEDIUM | 6.1 | 0.4% | Feb 6, 2020 | There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt... |
| CVE-2020-6854 | MEDIUM | 5.4 | 0.5% | Feb 5, 2020 | A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attac... |
| CVE-2020-3149 | MEDIUM | 4.8 | 0.6% | Feb 5, 2020 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an au... |
| CVE-2020-3120 | MEDIUM | 6.5 | 2.0% | Feb 5, 2020 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco... |
| CVE-2020-8506 | MEDIUM | 5.3 | 1.1% | Feb 5, 2020 | The Global TV application 2.3.2 for Android and 4.7.5 for iOS sends Unencrypted Analytics. |
| CVE-2020-7977 | MEDIUM | 5.3 | 0.8% | Feb 5, 2020 | GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions. |
| CVE-2020-7976 | MEDIUM | 5.3 | 0.9% | Feb 5, 2020 | GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control. |
| CVE-2020-7974 | MEDIUM | 5.3 | 0.9% | Feb 5, 2020 | GitLab EE 10.1 through 12.7.2 allows Information Disclosure. |
| CVE-2020-7973 | MEDIUM | 6.1 | 0.9% | Feb 5, 2020 | GitLab through 12.7.2 allows XSS. |
| CVE-2020-7971 | MEDIUM | 6.1 | 0.7% | Feb 5, 2020 | GitLab EE 11.0 and later through 12.7.2 allows XSS. |
| CVE-2020-7967 | MEDIUM | 4.3 | 0.7% | Feb 5, 2020 | GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2). |
| CVE-2020-7979 | MEDIUM | 5.3 | 0.9% | Feb 5, 2020 | GitLab EE 8.9 and later through 12.7.2 has Insecure Permission |
| CVE-2020-8632 | MEDIUM | 5.5 | 0.4% | Feb 5, 2020 | In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, ... |
| CVE-2020-8631 | MEDIUM | 5.5 | 0.4% | Feb 5, 2020 | cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict... |
| CVE-2020-8615 | MEDIUM | 6.5 | 8.8% | Feb 4, 2020 | A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves a... |
| CVE-2020-8124 | MEDIUM | 5.3 | 1.7% | Feb 4, 2020 | Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may all... |
| CVE-2020-8123 | MEDIUM | 4.9 | 1.1% | Feb 4, 2020 | A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin ri... |
| CVE-2020-8122 | MEDIUM | 4.3 | 0.7% | Feb 4, 2020 | A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share... |
| CVE-2020-8120 | MEDIUM | 6.1 | 0.9% | Feb 4, 2020 | A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation. |
| CVE-2020-8119 | MEDIUM | 4.3 | 0.9% | Feb 4, 2020 | Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is op... |
| CVE-2020-8118 | MEDIUM | 5 | 1.3% | Feb 4, 2020 | An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now