2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13337MEDIUM4.8An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload t...
CVE-2020-12676CRITICAL9.1FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assert...
CVE-2020-5982MEDIUM4.4NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) schedu...
CVE-2020-5981HIGH7.8NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x....
CVE-2020-5980HIGH7.8NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in multiple components in which a securely loa...
CVE-2020-5979HIGH7.8NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which...
CVE-2020-26541MEDIUM6.5The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protect...
CVE-2020-24628HIGH8.8A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8....
CVE-2020-24627MEDIUM5.4A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.
CVE-2020-24568MEDIUM6.5An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection i...
CVE-2020-15230MEDIUM6.5Vapor is a web framework for Swift. In Vapor before version 4.29.4, Attackers can access data at arbitrary filesystem pa...
CVE-2020-5422MEDIUM6.5BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH d...
CVE-2020-7070MEDIUM5.3In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cook...
CVE-2020-7069MEDIUM6.5In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_en...
CVE-2020-24356HIGH7.8`cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run...
CVE-2020-18191CRITICAL9.1GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimp...
CVE-2020-18190CRITICAL9.1Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/up...
CVE-2020-18185CRITICAL9.8class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a l...
CVE-2020-18184HIGH7.2In PluxXml V5.7,the theme edit function /PluXml/core/admin/parametres_edittpl.php allows remote attackers to execute arb...
CVE-2020-25623HIGH7.5Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP r...
CVE-2020-8110HIGH7.5A vulnerability has been discovered in the ceva_emu.cvd module that results from a lack of proper validation of user-sup...
CVE-2020-7738HIGH8.3All versions of package shiba are vulnerable to Arbitrary Code Execution due to the default usage of the function load()...
CVE-2020-7737CRITICAL9.8All versions of package safetydance are vulnerable to Prototype Pollution via the set function.
CVE-2020-7736CRITICAL9.8The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.
CVE-2020-26135MEDIUM6.1Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now