2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13952HIGH8.1In the course of work on the open source project it was discovered that authenticated users running queries against Hive...
CVE-2020-13336MEDIUM4.8An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored X...
CVE-2020-12870CRITICAL9.8RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.
CVE-2020-12869MEDIUM5.4RainbowFish PacsOne Server 6.8.4 allows XSS.
CVE-2020-12715HIGH8.8RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control.
CVE-2020-25816MEDIUM6.8HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their T...
CVE-2020-25626MEDIUM6.1A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer...
CVE-2020-14374HIGH8.8A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data funct...
CVE-2020-15849HIGH7.2Re:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTem...
CVE-2020-15488HIGH7.5Re:Desk 2.3 allows insecure file upload.
CVE-2020-14378LOW3.3An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large a...
CVE-2020-14377HIGH7.1A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-contr...
CVE-2020-14376HIGH7.8A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data ...
CVE-2020-14375HIGH7.8A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they desc...
CVE-2020-8256MEDIUM4.9A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain ...
CVE-2020-8243HIGH7.2A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to uploa...
CVE-2020-8238MEDIUM6.1A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could ...
CVE-2020-26163HIGH8.8BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover...
CVE-2020-26160HIGH7.5jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m...
CVE-2020-26158CRITICAL9.6Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This ...
CVE-2020-26157CRITICAL9.6Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code ...
CVE-2020-26154CRITICAL9.8url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC fil...
CVE-2020-26150HIGH7.5info.php in Logaritmo Aware CallManager 2012 allows remote attackers to obtain sensitive information via a direct reques...
CVE-2020-26149HIGH7.5NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a...
CVE-2020-26148HIGH7.5md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now