2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26270 | LOW | 3.3 | 0.2% | Dec 10, 2020 | In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length... |
| CVE-2020-26269 | HIGH | 7.5 | 0.7% | Dec 10, 2020 | In TensorFlow release candidate versions 2.4.0rc*, the general implementation for matching filesystem paths to globbing ... |
| CVE-2020-26268 | MEDIUM | 4.4 | 0.2% | Dec 10, 2020 | In affected versions of TensorFlow the tf.raw_ops.ImmutableConst operation returns a constant tensor created from a memo... |
| CVE-2020-26267 | HIGH | 7.8 | 0.2% | Dec 10, 2020 | In affected versions of TensorFlow the tf.raw_ops.DataFormatVecPermute API does not validate the src_format and dst_form... |
| CVE-2020-26266 | MEDIUM | 5.3 | 0.2% | Dec 10, 2020 | In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code... |
| CVE-2020-26201 | CRITICAL | 9.8 | 2.4% | Dec 10, 2020 | Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. Th... |
| CVE-2020-25967 | HIGH | 8.8 | 1.3% | Dec 10, 2020 | The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vu... |
| CVE-2020-19527 | CRITICAL | 9.8 | 1.5% | Dec 10, 2020 | iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/inst... |
| CVE-2020-19142 | CRITICAL | 9.8 | 1.5% | Dec 10, 2020 | iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install... |
| CVE-2020-16608 | CRITICAL | 9.6 | 4.3% | Dec 10, 2020 | Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in web... |
| CVE-2020-16196 | — | — | — | Dec 10, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-13526 | HIGH | 8.8 | 1.7% | Dec 10, 2020 | SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP r... |
| CVE-2020-26271 | LOW | 3.3 | 0.2% | Dec 10, 2020 | In affected versions of TensorFlow under certain cases, loading a saved model can result in accessing uninitialized memo... |
| CVE-2020-8920 | LOW | 3.5 | 0.4% | Dec 10, 2020 | An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 wh... |
| CVE-2020-8919 | LOW | 3.5 | 0.3% | Dec 10, 2020 | An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a mis... |
| CVE-2020-29667 | CRITICAL | 9.8 | 3.2% | Dec 10, 2020 | In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSI... |
| CVE-2020-29666 | MEDIUM | 5.3 | 1.4% | Dec 10, 2020 | In Lan ATMService M3 ATM Monitoring System 6.1.0, due to a directory-listing vulnerability, a remote attacker can view l... |
| CVE-2020-29668 | LOW | 3.7 | 2.0% | Dec 10, 2020 | Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except on... |
| CVE-2020-26407 | MEDIUM | 5.4 | 0.7% | Dec 10, 2020 | A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allo... |
| CVE-2020-24445 | CRITICAL | 9 | 2.5% | Dec 10, 2020 | AEM's Cloud Service offering, as well as version 6.5.6.0 (and below), are affected by a stored Cross-Site Scripting (XSS... |
| CVE-2020-24444 | MEDIUM | 5.8 | 2.1% | Dec 10, 2020 | AEM Forms SP6 add-on for AEM 6.5.6.0 and Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2)... |
| CVE-2020-12595 | MEDIUM | 4.9 | 0.9% | Dec 10, 2020 | An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remo... |
| CVE-2020-12594 | HIGH | 7.2 | 1.5% | Dec 10, 2020 | A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the s... |
| CVE-2020-2498 | MEDIUM | 6.1 | 0.6% | Dec 10, 2020 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certifica... |
| CVE-2020-2497 | MEDIUM | 6.1 | 1.0% | Dec 10, 2020 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Co... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now