2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13952 | HIGH | 8.1 | 2.0% | Sep 30, 2020 | In the course of work on the open source project it was discovered that authenticated users running queries against Hive... |
| CVE-2020-13336 | MEDIUM | 4.8 | 0.5% | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored X... |
| CVE-2020-12870 | CRITICAL | 9.8 | 1.6% | Sep 30, 2020 | RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page. |
| CVE-2020-12869 | MEDIUM | 5.4 | 0.6% | Sep 30, 2020 | RainbowFish PacsOne Server 6.8.4 allows XSS. |
| CVE-2020-12715 | HIGH | 8.8 | 1.2% | Sep 30, 2020 | RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control. |
| CVE-2020-25816 | MEDIUM | 6.8 | 1.0% | Sep 30, 2020 | HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their T... |
| CVE-2020-25626 | MEDIUM | 6.1 | 1.3% | Sep 30, 2020 | A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer... |
| CVE-2020-14374 | HIGH | 8.8 | 0.4% | Sep 30, 2020 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data funct... |
| CVE-2020-15849 | HIGH | 7.2 | 2.7% | Sep 30, 2020 | Re:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTem... |
| CVE-2020-15488 | HIGH | 7.5 | 1.0% | Sep 30, 2020 | Re:Desk 2.3 allows insecure file upload. |
| CVE-2020-14378 | LOW | 3.3 | 0.4% | Sep 30, 2020 | An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large a... |
| CVE-2020-14377 | HIGH | 7.1 | 0.4% | Sep 30, 2020 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-contr... |
| CVE-2020-14376 | HIGH | 7.8 | 0.4% | Sep 30, 2020 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data ... |
| CVE-2020-14375 | HIGH | 7.8 | 0.3% | Sep 30, 2020 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they desc... |
| CVE-2020-8256 | MEDIUM | 4.9 | 3.4% | Sep 30, 2020 | A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain ... |
| CVE-2020-8243 | HIGH | 7.2 | 90.8% | Sep 30, 2020 | A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to uploa... |
| CVE-2020-8238 | MEDIUM | 6.1 | 1.7% | Sep 30, 2020 | A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could ... |
| CVE-2020-26163 | HIGH | 8.8 | 1.5% | Sep 30, 2020 | BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover... |
| CVE-2020-26160 | HIGH | 7.5 | 2.1% | Sep 30, 2020 | jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m... |
| CVE-2020-26158 | CRITICAL | 9.6 | 1.9% | Sep 30, 2020 | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This ... |
| CVE-2020-26157 | CRITICAL | 9.6 | 1.9% | Sep 30, 2020 | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code ... |
| CVE-2020-26154 | CRITICAL | 9.8 | 3.6% | Sep 30, 2020 | url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC fil... |
| CVE-2020-26150 | HIGH | 7.5 | 1.3% | Sep 30, 2020 | info.php in Logaritmo Aware CallManager 2012 allows remote attackers to obtain sensitive information via a direct reques... |
| CVE-2020-26149 | HIGH | 7.5 | 1.5% | Sep 30, 2020 | NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a... |
| CVE-2020-26148 | HIGH | 7.5 | 1.4% | Sep 30, 2020 | md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now