2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13317MEDIUM4.9A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the Graph...
CVE-2020-13314MEDIUM5.3A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Omniauth endpoint allowed a ...
CVE-2020-13313MEDIUM4.3A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer ...
CVE-2020-13312CRITICAL9.8A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerabl...
CVE-2020-13311MEDIUM4.3A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser att...
CVE-2020-10229HIGH8.8A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such a...
CVE-2020-10228HIGH8.8A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, re...
CVE-2020-10227MEDIUM6.1A cross-site scripting (XSS) vulnerability in the messages module of vtecrm vtenext 19 CE allows attackers to inject arb...
CVE-2020-25576CRITICAL9.8An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandle...
CVE-2020-25575CRITICAL9.8An issue was discovered in the failure crate through 0.1.5 for Rust. It may introduce "compatibility hazards" in some ap...
CVE-2020-25574HIGH7.5An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() could resu...
CVE-2020-25573CRITICAL9.8An issue was discovered in the linked-hash-map crate before 0.5.3 for Rust. It creates an uninitialized NonNull pointer,...
CVE-2020-24457HIGH7.6Logic error in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processors may allow an unauthenticated ...
CVE-2020-13318HIGH7.3A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration wa...
CVE-2020-13316MEDIUM4.3A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-...
CVE-2020-13300CRITICAL10GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in ...
CVE-2020-13299HIGH8.1A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revo...
CVE-2020-13289MEDIUM5.4A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid usernam...
CVE-2020-13287MEDIUM4.3A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could s...
CVE-2020-13284MEDIUM6.5A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI...
CVE-2020-0570HIGH7.3Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potential...
CVE-2020-21845MEDIUM6.1Codoforum 4.8.3 allows HTML Injection in the 'admin dashboard Manage users Section.'
CVE-2020-25380MEDIUM5.4Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 is affected by: Cross Site Scripting (XSS) via the 'Recal...
CVE-2020-25379HIGH8.8Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' paramet...
CVE-2020-25378MEDIUM6.1Wordpress Plugin Store / AccessPress Themes WP Floating Menu V1.3.0 is affected by: Cross Site Scripting (XSS) via the i...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now