2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13337 | MEDIUM | 4.8 | 0.7% | Oct 2, 2020 | An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload t... |
| CVE-2020-12676 | CRITICAL | 9.1 | 2.9% | Oct 2, 2020 | FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assert... |
| CVE-2020-5982 | MEDIUM | 4.4 | 0.3% | Oct 2, 2020 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) schedu... |
| CVE-2020-5981 | HIGH | 7.8 | 0.3% | Oct 2, 2020 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.... |
| CVE-2020-5980 | HIGH | 7.8 | 0.4% | Oct 2, 2020 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in multiple components in which a securely loa... |
| CVE-2020-5979 | HIGH | 7.8 | 0.3% | Oct 2, 2020 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which... |
| CVE-2020-26541 | MEDIUM | 6.5 | 0.5% | Oct 2, 2020 | The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protect... |
| CVE-2020-24628 | HIGH | 8.8 | 1.3% | Oct 2, 2020 | A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.... |
| CVE-2020-24627 | MEDIUM | 5.4 | 0.5% | Oct 2, 2020 | A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3. |
| CVE-2020-24568 | MEDIUM | 6.5 | 0.8% | Oct 2, 2020 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection i... |
| CVE-2020-15230 | MEDIUM | 6.5 | 1.5% | Oct 2, 2020 | Vapor is a web framework for Swift. In Vapor before version 4.29.4, Attackers can access data at arbitrary filesystem pa... |
| CVE-2020-5422 | MEDIUM | 6.5 | 0.9% | Oct 2, 2020 | BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH d... |
| CVE-2020-7070 | MEDIUM | 5.3 | 5.0% | Oct 2, 2020 | In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cook... |
| CVE-2020-7069 | MEDIUM | 6.5 | 2.0% | Oct 2, 2020 | In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_en... |
| CVE-2020-24356 | HIGH | 7.8 | 0.3% | Oct 2, 2020 | `cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run... |
| CVE-2020-18191 | CRITICAL | 9.1 | 2.0% | Oct 2, 2020 | GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimp... |
| CVE-2020-18190 | CRITICAL | 9.1 | 1.9% | Oct 2, 2020 | Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/up... |
| CVE-2020-18185 | CRITICAL | 9.8 | 1.7% | Oct 2, 2020 | class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a l... |
| CVE-2020-18184 | HIGH | 7.2 | 1.4% | Oct 2, 2020 | In PluxXml V5.7,the theme edit function /PluXml/core/admin/parametres_edittpl.php allows remote attackers to execute arb... |
| CVE-2020-25623 | HIGH | 7.5 | 3.1% | Oct 2, 2020 | Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP r... |
| CVE-2020-8110 | HIGH | 7.5 | 0.9% | Oct 2, 2020 | A vulnerability has been discovered in the ceva_emu.cvd module that results from a lack of proper validation of user-sup... |
| CVE-2020-7738 | HIGH | 8.3 | 1.5% | Oct 2, 2020 | All versions of package shiba are vulnerable to Arbitrary Code Execution due to the default usage of the function load()... |
| CVE-2020-7737 | CRITICAL | 9.8 | 1.3% | Oct 2, 2020 | All versions of package safetydance are vulnerable to Prototype Pollution via the set function. |
| CVE-2020-7736 | CRITICAL | 9.8 | 1.5% | Oct 2, 2020 | The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function. |
| CVE-2020-26135 | MEDIUM | 6.1 | 1.0% | Oct 2, 2020 | Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now