2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35135HIGH8.8The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF.
CVE-2020-35132MEDIUM5.4An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be ...
CVE-2020-35127MEDIUM5.4Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS.
CVE-2020-27786HIGH7.8A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permission...
CVE-2020-26411MEDIUM4.3A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 t...
CVE-2020-35126MEDIUM4.8Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI...
CVE-2020-27828HIGH7.8There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker coul...
CVE-2020-26417MEDIUM5.3Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This aff...
CVE-2020-26416MEDIUM4.4Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms v...
CVE-2020-26415MEDIUM4.3Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via ...
CVE-2020-26413MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclo...
CVE-2020-26412MEDIUM4.3Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics sta...
CVE-2020-26408MEDIUM5.3A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=...
CVE-2020-13556CRITICAL9.8An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and de...
CVE-2020-13530HIGH7.5A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and d...
CVE-2020-13520HIGH7.8An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary US...
CVE-2020-13357MEDIUM4.3An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed ...
CVE-2020-9301HIGH8.8Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to versio...
CVE-2020-24447HIGH7Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability ...
CVE-2020-24440HIGH7Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitr...
CVE-2020-26409MEDIUM6.5A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to tr...
CVE-2020-25838MEDIUM6.5Unauthorized disclosure of sensitive information vulnerability in Micro Focus Filr product. Affecting all 3.x and 4.x ve...
CVE-2020-25191HIGH7.5Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user...
CVE-2020-24637HIGH7.2Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation...
CVE-2020-24634CRITICAL9.8An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Ar...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now