2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35135 | HIGH | 8.8 | 0.9% | Dec 11, 2020 | The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF. |
| CVE-2020-35132 | MEDIUM | 5.4 | 1.3% | Dec 11, 2020 | An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be ... |
| CVE-2020-35127 | MEDIUM | 5.4 | 0.6% | Dec 11, 2020 | Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS. |
| CVE-2020-27786 | HIGH | 7.8 | 1.7% | Dec 11, 2020 | A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permission... |
| CVE-2020-26411 | MEDIUM | 4.3 | 1.2% | Dec 11, 2020 | A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 t... |
| CVE-2020-35126 | MEDIUM | 4.8 | 0.7% | Dec 11, 2020 | Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI... |
| CVE-2020-27828 | HIGH | 7.8 | 1.4% | Dec 11, 2020 | There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker coul... |
| CVE-2020-26417 | MEDIUM | 5.3 | 1.2% | Dec 11, 2020 | Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This aff... |
| CVE-2020-26416 | MEDIUM | 4.4 | 0.3% | Dec 11, 2020 | Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms v... |
| CVE-2020-26415 | MEDIUM | 4.3 | 0.8% | Dec 11, 2020 | Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via ... |
| CVE-2020-26413 | MEDIUM | 5.3 | 33.8% | Dec 11, 2020 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclo... |
| CVE-2020-26412 | MEDIUM | 4.3 | 1.0% | Dec 11, 2020 | Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics sta... |
| CVE-2020-26408 | MEDIUM | 5.3 | 1.0% | Dec 11, 2020 | A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=... |
| CVE-2020-13556 | CRITICAL | 9.8 | 4.5% | Dec 11, 2020 | An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and de... |
| CVE-2020-13530 | HIGH | 7.5 | 2.1% | Dec 11, 2020 | A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and d... |
| CVE-2020-13520 | HIGH | 7.8 | 2.0% | Dec 11, 2020 | An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary US... |
| CVE-2020-13357 | MEDIUM | 4.3 | 0.8% | Dec 11, 2020 | An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed ... |
| CVE-2020-9301 | HIGH | 8.8 | 1.5% | Dec 11, 2020 | Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to versio... |
| CVE-2020-24447 | HIGH | 7 | 0.8% | Dec 11, 2020 | Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability ... |
| CVE-2020-24440 | HIGH | 7 | 0.6% | Dec 11, 2020 | Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitr... |
| CVE-2020-26409 | MEDIUM | 6.5 | 1.2% | Dec 11, 2020 | A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to tr... |
| CVE-2020-25838 | MEDIUM | 6.5 | 0.8% | Dec 11, 2020 | Unauthorized disclosure of sensitive information vulnerability in Micro Focus Filr product. Affecting all 3.x and 4.x ve... |
| CVE-2020-25191 | HIGH | 7.5 | 1.1% | Dec 11, 2020 | Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user... |
| CVE-2020-24637 | HIGH | 7.2 | 1.6% | Dec 11, 2020 | Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation... |
| CVE-2020-24634 | CRITICAL | 9.8 | 2.1% | Dec 11, 2020 | An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Ar... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now