2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-19670 | MEDIUM | 4.9 | 0.9% | Sep 30, 2020 | In Niushop B2B2C Multi-Business Basic Edition V1.11, authentication can be bypassed, causing administrators to reset any... |
| CVE-2020-15595 | MEDIUM | 4.3 | 2.2% | Sep 30, 2020 | An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to ... |
| CVE-2020-15594 | MEDIUM | 4.3 | 1.8% | Sep 30, 2020 | An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration fe... |
| CVE-2020-15487 | CRITICAL | 9.8 | 3.7% | Sep 30, 2020 | Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protec... |
| CVE-2020-14030 | HIGH | 7.2 | 1.8% | Sep 30, 2020 | An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the ... |
| CVE-2020-13953 | MEDIUM | 5.3 | 2.7% | Sep 30, 2020 | In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder... |
| CVE-2020-13951 | HIGH | 7.5 | 69.1% | Sep 30, 2020 | Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. |
| CVE-2020-13794 | MEDIUM | 4.3 | 1.3% | Sep 30, 2020 | Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor. |
| CVE-2020-13658 | HIGH | 8 | 0.5% | Sep 30, 2020 | In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to... |
| CVE-2020-13506 | — | — | — | Sep 30, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-13331 | MEDIUM | 5.4 | 0.7% | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in... |
| CVE-2020-13330 | MEDIUM | 5.4 | 0.6% | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in im... |
| CVE-2020-13329 | MEDIUM | 6.5 | 0.6% | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stor... |
| CVE-2020-13328 | MEDIUM | 4.8 | 0.6% | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. GitLab was vulnerable to... |
| CVE-2020-13326 | MEDIUM | 4.3 | 0.7% | Sep 30, 2020 | A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github pro... |
| CVE-2020-13325 | HIGH | 7.1 | 0.9% | Sep 30, 2020 | A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting ... |
| CVE-2020-13324 | MEDIUM | 6.5 | 1.0% | Sep 30, 2020 | A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user... |
| CVE-2020-13323 | HIGH | 7.7 | 1.1% | Sep 30, 2020 | A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be r... |
| CVE-2020-13322 | HIGH | 7.2 | 1.1% | Sep 30, 2020 | A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthoriz... |
| CVE-2020-13321 | HIGH | 8.3 | 1.4% | Sep 30, 2020 | A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing... |
| CVE-2020-13320 | MEDIUM | 6.5 | 1.0% | Sep 30, 2020 | An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to... |
| CVE-2020-13319 | MEDIUM | 4.3 | 0.8% | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check... |
| CVE-2020-13296 | HIGH | 8.8 | 1.6% | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper ... |
| CVE-2020-12506 | CRITICAL | 9.1 | 1.5% | Sep 30, 2020 | Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the se... |
| CVE-2020-12505 | HIGH | 8.2 | 1.2% | Sep 30, 2020 | Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some s... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now