2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15176HIGH8.6In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does no...
CVE-2020-15175CRITICAL9.1In GLPI before version 9.5.2, the `​pluginimage.send.php​` endpoint allows a user to specify an image from a plugin. The...
CVE-2020-26880HIGH7.8Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying...
CVE-2020-26876HIGH7.5The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for cour...
CVE-2020-17551MEDIUM4.8ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution.
CVE-2020-26870MEDIUM6.1Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily...
CVE-2020-26596HIGH8.8The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to exe...
CVE-2020-24246HIGH7.5Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php...
CVE-2020-13342LOW2.7An issue has been discovered in GitLab affecting versions prior to 13.2.10, 13.3.7 and 13.4.2: Lack of Rate Limiting at ...
CVE-2020-11800CRITICAL9.8Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.
CVE-2020-24722MEDIUM5.9An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in CO...
CVE-2020-14355MEDIUM6.6Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display syste...
CVE-2020-25343MEDIUM5.4Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script o...
CVE-2020-13347CRITICAL9.1A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the ...
CVE-2020-13346MEDIUM6.5Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allow...
CVE-2020-13335MEDIUM4.3Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account w...
CVE-2020-13334HIGH7.5In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/gr...
CVE-2020-13332Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-25985HIGH8.1MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion. Any authenticated user can delete files on and off the webserv...
CVE-2020-7742HIGH7.5This affects the package simpl-schema before 1.10.2.
CVE-2020-14183MEDIUM4.3Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jir...
CVE-2020-26607CRITICAL9.8An issue was discovered in TimaService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. PendingInten...
CVE-2020-26606HIGH7.5An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. An attacker can ac...
CVE-2020-26605HIGH7.5An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Exynos chipsets) software. They allow attack...
CVE-2020-26604HIGH7.5An issue was discovered in SystemUI on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Pendin...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now