2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10776 | MEDIUM | 4.8 | 0.8% | Nov 17, 2020 | A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri para... |
| CVE-2020-26406 | MEDIUM | 5.3 | 1.4% | Nov 17, 2020 | Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This inf... |
| CVE-2020-25834 | MEDIUM | 5.4 | 0.7% | Nov 17, 2020 | Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability coul... |
| CVE-2020-13358 | MEDIUM | 5.5 | 0.3% | Nov 17, 2020 | A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access t... |
| CVE-2020-13354 | MEDIUM | 4.3 | 1.4% | Nov 17, 2020 | A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name che... |
| CVE-2020-13353 | LOW | 3.2 | 0.3% | Nov 17, 2020 | When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79... |
| CVE-2020-13352 | MEDIUM | 5.3 | 1.2% | Nov 17, 2020 | Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to pu... |
| CVE-2020-11860 | MEDIUM | 6.1 | 0.6% | Nov 17, 2020 | Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vul... |
| CVE-2020-26225 | MEDIUM | 6.1 | 0.9% | Nov 16, 2020 | In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web bro... |
| CVE-2020-26224 | HIGH | 7.5 | 1.7% | Nov 16, 2020 | In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logg... |
| CVE-2020-28693 | HIGH | 8.8 | 2.5% | Nov 16, 2020 | An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code t... |
| CVE-2020-27486 | CRITICAL | 9.9 | 1.9% | Nov 16, 2020 | Garmin Forerunner 235 before 8.20 is affected by: Buffer Overflow. The component is: ConnectIQ TVM. The attack vector is... |
| CVE-2020-27485 | CRITICAL | 9.9 | 1.6% | Nov 16, 2020 | Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector ... |
| CVE-2020-27484 | CRITICAL | 9.9 | 1.7% | Nov 16, 2020 | Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow. The component is: ConnectIQ TVM. The attack vector i... |
| CVE-2020-27483 | CRITICAL | 9.9 | 2.1% | Nov 16, 2020 | Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector ... |
| CVE-2020-26217 | HIGH | 8.8 | 85.0% | Nov 16, 2020 | XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to ru... |
| CVE-2020-5424 | — | — | — | Nov 16, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-26510 | CRITICAL | 9.8 | 2.1% | Nov 16, 2020 | Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for depl... |
| CVE-2020-26509 | HIGH | 7.5 | 1.1% | Nov 16, 2020 | Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service. |
| CVE-2020-26508 | CRITICAL | 9.8 | 1.1% | Nov 16, 2020 | The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials v... |
| CVE-2020-28692 | HIGH | 7.2 | 1.6% | Nov 16, 2020 | In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for exec... |
| CVE-2020-23490 | HIGH | 7.5 | 2.6% | Nov 16, 2020 | There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can... |
| CVE-2020-23489 | HIGH | 8.8 | 2.3% | Nov 16, 2020 | The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion ... |
| CVE-2020-4763 | MEDIUM | 4.3 | 1.0% | Nov 16, 2020 | IBM Sterling File Gateway 6.0.0.0 through 6.0.3.2 and 2.2.0.0 through 2.2.6.5 does not set the secure attribute on autho... |
| CVE-2020-4705 | MEDIUM | 4.8 | 0.5% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to cross-... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now