2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15176 | HIGH | 8.6 | 1.1% | Oct 7, 2020 | In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does no... |
| CVE-2020-15175 | CRITICAL | 9.1 | 70.9% | Oct 7, 2020 | In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. The... |
| CVE-2020-26880 | HIGH | 7.8 | 0.3% | Oct 7, 2020 | Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying... |
| CVE-2020-26876 | HIGH | 7.5 | 9.2% | Oct 7, 2020 | The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for cour... |
| CVE-2020-17551 | MEDIUM | 4.8 | 1.1% | Oct 7, 2020 | ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution. |
| CVE-2020-26870 | MEDIUM | 6.1 | 4.5% | Oct 7, 2020 | Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily... |
| CVE-2020-26596 | HIGH | 8.8 | 5.4% | Oct 7, 2020 | The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to exe... |
| CVE-2020-24246 | HIGH | 7.5 | 1.3% | Oct 7, 2020 | Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php... |
| CVE-2020-13342 | LOW | 2.7 | 0.9% | Oct 7, 2020 | An issue has been discovered in GitLab affecting versions prior to 13.2.10, 13.3.7 and 13.4.2: Lack of Rate Limiting at ... |
| CVE-2020-11800 | CRITICAL | 9.8 | 9.2% | Oct 7, 2020 | Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code. |
| CVE-2020-24722 | MEDIUM | 5.9 | 2.4% | Oct 7, 2020 | An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in CO... |
| CVE-2020-14355 | MEDIUM | 6.6 | 2.5% | Oct 7, 2020 | Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display syste... |
| CVE-2020-25343 | MEDIUM | 5.4 | 0.7% | Oct 7, 2020 | Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script o... |
| CVE-2020-13347 | CRITICAL | 9.1 | 2.3% | Oct 7, 2020 | A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the ... |
| CVE-2020-13346 | MEDIUM | 6.5 | 1.3% | Oct 7, 2020 | Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allow... |
| CVE-2020-13335 | MEDIUM | 4.3 | 0.8% | Oct 7, 2020 | Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account w... |
| CVE-2020-13334 | HIGH | 7.5 | 1.5% | Oct 7, 2020 | In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/gr... |
| CVE-2020-13332 | — | — | — | Oct 7, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-25985 | HIGH | 8.1 | 1.7% | Oct 7, 2020 | MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion. Any authenticated user can delete files on and off the webserv... |
| CVE-2020-7742 | HIGH | 7.5 | 1.5% | Oct 7, 2020 | This affects the package simpl-schema before 1.10.2. |
| CVE-2020-14183 | MEDIUM | 4.3 | 1.3% | Oct 6, 2020 | Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jir... |
| CVE-2020-26607 | CRITICAL | 9.8 | 0.5% | Oct 6, 2020 | An issue was discovered in TimaService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. PendingInten... |
| CVE-2020-26606 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. An attacker can ac... |
| CVE-2020-26605 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Exynos chipsets) software. They allow attack... |
| CVE-2020-26604 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered in SystemUI on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Pendin... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now