2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26270LOW3.3In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length...
CVE-2020-26269HIGH7.5In TensorFlow release candidate versions 2.4.0rc*, the general implementation for matching filesystem paths to globbing ...
CVE-2020-26268MEDIUM4.4In affected versions of TensorFlow the tf.raw_ops.ImmutableConst operation returns a constant tensor created from a memo...
CVE-2020-26267HIGH7.8In affected versions of TensorFlow the tf.raw_ops.DataFormatVecPermute API does not validate the src_format and dst_form...
CVE-2020-26266MEDIUM5.3In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code...
CVE-2020-26201CRITICAL9.8Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. Th...
CVE-2020-25967HIGH8.8The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vu...
CVE-2020-19527CRITICAL9.8iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/inst...
CVE-2020-19142CRITICAL9.8iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install...
CVE-2020-16608CRITICAL9.6Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in web...
CVE-2020-16196Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-13526HIGH8.8SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP r...
CVE-2020-26271LOW3.3In affected versions of TensorFlow under certain cases, loading a saved model can result in accessing uninitialized memo...
CVE-2020-8920LOW3.5An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 wh...
CVE-2020-8919LOW3.5An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a mis...
CVE-2020-29667CRITICAL9.8In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSI...
CVE-2020-29666MEDIUM5.3In Lan ATMService M3 ATM Monitoring System 6.1.0, due to a directory-listing vulnerability, a remote attacker can view l...
CVE-2020-29668LOW3.7Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except on...
CVE-2020-26407MEDIUM5.4A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allo...
CVE-2020-24445CRITICAL9AEM's Cloud Service offering, as well as version 6.5.6.0 (and below), are affected by a stored Cross-Site Scripting (XSS...
CVE-2020-24444MEDIUM5.8AEM Forms SP6 add-on for AEM 6.5.6.0 and Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2)...
CVE-2020-12595MEDIUM4.9An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remo...
CVE-2020-12594HIGH7.2A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the s...
CVE-2020-2498MEDIUM6.1If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certifica...
CVE-2020-2497MEDIUM6.1If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Co...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now