2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28914HIGH7.1An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath vol...
CVE-2020-28092MEDIUM6.1PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&s...
CVE-2020-28130CRITICAL9.8An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the...
CVE-2020-28129MEDIUM6.1Stored Cross-site scripting (XSS) vulnerability in SourceCodester Gym Management System 1.0 allows users to inject and s...
CVE-2020-26553CRITICAL9.8An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary fil...
CVE-2020-26552HIGH7.5An issue was discovered in Aviatrix Controller before R6.0.2483. Multiple executable files, that implement API endpoints...
CVE-2020-26551HIGH7.5An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.
CVE-2020-26550HIGH7.5An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated s...
CVE-2020-26549HIGH7.5An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests t...
CVE-2020-26548HIGH8.8An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can ...
CVE-2020-26216MEDIUM6.1TYPO3 Fluid before versions 2.0.8, 2.1.7, 2.2.4, 2.3.7, 2.4.4, 2.5.11 and 2.6.10 is vulnerable to Cross-Site Scripting. ...
CVE-2020-25890MEDIUM6.1The web application of Kyocera printer (ECOSYS M2640IDW) is affected by Stored XSS vulnerability, discovered in the addi...
CVE-2020-28136HIGH8.8An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote...
CVE-2020-28133CRITICAL9.8An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication ...
CVE-2020-25988MEDIUM6.5UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' wh...
CVE-2020-28140CRITICAL9.8SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Product...
CVE-2020-28139MEDIUM6.1SourceCodester Online Clothing Store 1.0 is affected by a cross-site scripting (XSS) vulnerability via a Offer Detail fi...
CVE-2020-28138CRITICAL9.8SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.
CVE-2020-26405HIGH7.1Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to sa...
CVE-2020-13349MEDIUM4.3An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a f...
CVE-2020-13348MEDIUM5.7An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could ...
CVE-2020-26701MEDIUM5.4Cross-site scripting (XSS) vulnerability in Dashboards section in Kaa IoT Platform v1.2.0 allows remote attackers to inj...
CVE-2020-25400HIGH7.5Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to acce...
CVE-2020-13351MEDIUM6.5Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names...
CVE-2020-13350MEDIUM4.3CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instan...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now