2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-19670MEDIUM4.9In Niushop B2B2C Multi-Business Basic Edition V1.11, authentication can be bypassed, causing administrators to reset any...
CVE-2020-15595MEDIUM4.3An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to ...
CVE-2020-15594MEDIUM4.3An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration fe...
CVE-2020-15487CRITICAL9.8Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protec...
CVE-2020-14030HIGH7.2An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the ...
CVE-2020-13953MEDIUM5.3In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder...
CVE-2020-13951HIGH7.5Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
CVE-2020-13794MEDIUM4.3Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.
CVE-2020-13658HIGH8In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to...
CVE-2020-13506Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-13331MEDIUM5.4An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in...
CVE-2020-13330MEDIUM5.4An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in im...
CVE-2020-13329MEDIUM6.5An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stor...
CVE-2020-13328MEDIUM4.8An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. GitLab was vulnerable to...
CVE-2020-13326MEDIUM4.3A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github pro...
CVE-2020-13325HIGH7.1A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting ...
CVE-2020-13324MEDIUM6.5A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user...
CVE-2020-13323HIGH7.7A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be r...
CVE-2020-13322HIGH7.2A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthoriz...
CVE-2020-13321HIGH8.3A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing...
CVE-2020-13320MEDIUM6.5An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to...
CVE-2020-13319MEDIUM4.3An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check...
CVE-2020-13296HIGH8.8An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper ...
CVE-2020-12506CRITICAL9.1Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the se...
CVE-2020-12505HIGH8.2Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some s...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now