2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28914 | HIGH | 7.1 | 0.4% | Nov 17, 2020 | An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath vol... |
| CVE-2020-28092 | MEDIUM | 6.1 | 2.2% | Nov 17, 2020 | PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&s... |
| CVE-2020-28130 | CRITICAL | 9.8 | 6.3% | Nov 17, 2020 | An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the... |
| CVE-2020-28129 | MEDIUM | 6.1 | 0.9% | Nov 17, 2020 | Stored Cross-site scripting (XSS) vulnerability in SourceCodester Gym Management System 1.0 allows users to inject and s... |
| CVE-2020-26553 | CRITICAL | 9.8 | 1.7% | Nov 17, 2020 | An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary fil... |
| CVE-2020-26552 | HIGH | 7.5 | 1.2% | Nov 17, 2020 | An issue was discovered in Aviatrix Controller before R6.0.2483. Multiple executable files, that implement API endpoints... |
| CVE-2020-26551 | HIGH | 7.5 | 0.9% | Nov 17, 2020 | An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file. |
| CVE-2020-26550 | HIGH | 7.5 | 1.5% | Nov 17, 2020 | An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated s... |
| CVE-2020-26549 | HIGH | 7.5 | 1.5% | Nov 17, 2020 | An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests t... |
| CVE-2020-26548 | HIGH | 8.8 | 1.4% | Nov 17, 2020 | An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can ... |
| CVE-2020-26216 | MEDIUM | 6.1 | 1.0% | Nov 17, 2020 | TYPO3 Fluid before versions 2.0.8, 2.1.7, 2.2.4, 2.3.7, 2.4.4, 2.5.11 and 2.6.10 is vulnerable to Cross-Site Scripting. ... |
| CVE-2020-25890 | MEDIUM | 6.1 | 1.5% | Nov 17, 2020 | The web application of Kyocera printer (ECOSYS M2640IDW) is affected by Stored XSS vulnerability, discovered in the addi... |
| CVE-2020-28136 | HIGH | 8.8 | 2.9% | Nov 17, 2020 | An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote... |
| CVE-2020-28133 | CRITICAL | 9.8 | 2.1% | Nov 17, 2020 | An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication ... |
| CVE-2020-25988 | MEDIUM | 6.5 | 3.0% | Nov 17, 2020 | UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' wh... |
| CVE-2020-28140 | CRITICAL | 9.8 | 1.8% | Nov 17, 2020 | SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Product... |
| CVE-2020-28139 | MEDIUM | 6.1 | 0.8% | Nov 17, 2020 | SourceCodester Online Clothing Store 1.0 is affected by a cross-site scripting (XSS) vulnerability via a Offer Detail fi... |
| CVE-2020-28138 | CRITICAL | 9.8 | 2.0% | Nov 17, 2020 | SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php. |
| CVE-2020-26405 | HIGH | 7.1 | 1.4% | Nov 17, 2020 | Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to sa... |
| CVE-2020-13349 | MEDIUM | 4.3 | 0.9% | Nov 17, 2020 | An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a f... |
| CVE-2020-13348 | MEDIUM | 5.7 | 0.8% | Nov 17, 2020 | An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could ... |
| CVE-2020-26701 | MEDIUM | 5.4 | 0.9% | Nov 17, 2020 | Cross-site scripting (XSS) vulnerability in Dashboards section in Kaa IoT Platform v1.2.0 allows remote attackers to inj... |
| CVE-2020-25400 | HIGH | 7.5 | 1.9% | Nov 17, 2020 | Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to acce... |
| CVE-2020-13351 | MEDIUM | 6.5 | 1.3% | Nov 17, 2020 | Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names... |
| CVE-2020-13350 | MEDIUM | 4.3 | 0.7% | Nov 17, 2020 | CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instan... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now