2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-16101HIGH7.5It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out...
CVE-2020-16100HIGH7.5It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websoc...
CVE-2020-16099MEDIUM4.3In Gallagher Command Centre v8.20 prior to v8.20.1093(MR2) it is possible to create Guard Tour events that when accessed...
CVE-2020-16098CRITICAL9.8It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions ...
CVE-2020-16097MEDIUM4.6On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8....
CVE-2020-16096HIGH7.7In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(...
CVE-2020-14345HIGH7.8A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead...
CVE-2020-24925HIGH7.5A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3. An attacker is able to view the pa...
CVE-2020-24924MEDIUM5.4A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user ses...
CVE-2020-13308LOW2.7A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authenticat...
CVE-2020-13307MEDIUM4.7A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not revoking current use...
CVE-2020-13303MEDIUM6.5A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of per...
CVE-2020-8927MEDIUM6.5A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of...
CVE-2020-15590HIGH7.5A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to by...
CVE-2020-13315HIGH7.5A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not r...
CVE-2020-13310MEDIUM6.5A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the g...
CVE-2020-13309HIGH8.8A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SS...
CVE-2020-13306HIGH7.5A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abu...
CVE-2020-13305MEDIUM4.3A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not invalidating project...
CVE-2020-13304HIGH7.2A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret...
CVE-2020-13302HIGH7.2A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was...
CVE-2020-13301MEDIUM4.8A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored X...
CVE-2020-13298MEDIUM5.8A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality ...
CVE-2020-13297MEDIUM5.4A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. When 2 factor authentication was en...
CVE-2020-11881HIGH7.5An array index error in MikroTik RouterOS 6.41.3 through 6.46.5, and 7.x through 7.0 Beta5, allows an unauthenticated re...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now