2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10776MEDIUM4.8A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri para...
CVE-2020-26406MEDIUM5.3Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This inf...
CVE-2020-25834MEDIUM5.4Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability coul...
CVE-2020-13358MEDIUM5.5A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access t...
CVE-2020-13354MEDIUM4.3A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name che...
CVE-2020-13353LOW3.2When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79...
CVE-2020-13352MEDIUM5.3Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to pu...
CVE-2020-11860MEDIUM6.1Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vul...
CVE-2020-26225MEDIUM6.1In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web bro...
CVE-2020-26224HIGH7.5In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logg...
CVE-2020-28693HIGH8.8An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code t...
CVE-2020-27486CRITICAL9.9Garmin Forerunner 235 before 8.20 is affected by: Buffer Overflow. The component is: ConnectIQ TVM. The attack vector is...
CVE-2020-27485CRITICAL9.9Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector ...
CVE-2020-27484CRITICAL9.9Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow. The component is: ConnectIQ TVM. The attack vector i...
CVE-2020-27483CRITICAL9.9Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector ...
CVE-2020-26217HIGH8.8XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to ru...
CVE-2020-5424Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-26510CRITICAL9.8Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for depl...
CVE-2020-26509HIGH7.5Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service.
CVE-2020-26508CRITICAL9.8The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials v...
CVE-2020-28692HIGH7.2In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for exec...
CVE-2020-23490HIGH7.5There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can...
CVE-2020-23489HIGH8.8The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion ...
CVE-2020-4763MEDIUM4.3IBM Sterling File Gateway 6.0.0.0 through 6.0.3.2 and 2.2.0.0 through 2.2.6.5 does not set the secure attribute on autho...
CVE-2020-4705MEDIUM4.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to cross-...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now