2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13317 | MEDIUM | 4.9 | 1.4% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the Graph... |
| CVE-2020-13314 | MEDIUM | 5.3 | 1.3% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Omniauth endpoint allowed a ... |
| CVE-2020-13313 | MEDIUM | 4.3 | 1.0% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer ... |
| CVE-2020-13312 | CRITICAL | 9.8 | 0.9% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerabl... |
| CVE-2020-13311 | MEDIUM | 4.3 | 1.5% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser att... |
| CVE-2020-10229 | HIGH | 8.8 | 0.8% | Sep 14, 2020 | A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such a... |
| CVE-2020-10228 | HIGH | 8.8 | 2.9% | Sep 14, 2020 | A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, re... |
| CVE-2020-10227 | MEDIUM | 6.1 | 1.1% | Sep 14, 2020 | A cross-site scripting (XSS) vulnerability in the messages module of vtecrm vtenext 19 CE allows attackers to inject arb... |
| CVE-2020-25576 | CRITICAL | 9.8 | 1.6% | Sep 14, 2020 | An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandle... |
| CVE-2020-25575 | CRITICAL | 9.8 | 2.9% | Sep 14, 2020 | An issue was discovered in the failure crate through 0.1.5 for Rust. It may introduce "compatibility hazards" in some ap... |
| CVE-2020-25574 | HIGH | 7.5 | 2.4% | Sep 14, 2020 | An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() could resu... |
| CVE-2020-25573 | CRITICAL | 9.8 | 1.8% | Sep 14, 2020 | An issue was discovered in the linked-hash-map crate before 0.5.3 for Rust. It creates an uninitialized NonNull pointer,... |
| CVE-2020-24457 | HIGH | 7.6 | 0.4% | Sep 14, 2020 | Logic error in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processors may allow an unauthenticated ... |
| CVE-2020-13318 | HIGH | 7.3 | 1.0% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration wa... |
| CVE-2020-13316 | MEDIUM | 4.3 | 1.4% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-... |
| CVE-2020-13300 | CRITICAL | 10 | 1.3% | Sep 14, 2020 | GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in ... |
| CVE-2020-13299 | HIGH | 8.1 | 1.2% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revo... |
| CVE-2020-13289 | MEDIUM | 5.4 | 0.7% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid usernam... |
| CVE-2020-13287 | MEDIUM | 4.3 | 1.2% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could s... |
| CVE-2020-13284 | MEDIUM | 6.5 | 1.1% | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI... |
| CVE-2020-0570 | HIGH | 7.3 | 0.6% | Sep 14, 2020 | Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potential... |
| CVE-2020-21845 | MEDIUM | 6.1 | 0.8% | Sep 14, 2020 | Codoforum 4.8.3 allows HTML Injection in the 'admin dashboard Manage users Section.' |
| CVE-2020-25380 | MEDIUM | 5.4 | 0.7% | Sep 14, 2020 | Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 is affected by: Cross Site Scripting (XSS) via the 'Recal... |
| CVE-2020-25379 | HIGH | 8.8 | 1.9% | Sep 14, 2020 | Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' paramet... |
| CVE-2020-25378 | MEDIUM | 6.1 | 0.9% | Sep 14, 2020 | Wordpress Plugin Store / AccessPress Themes WP Floating Menu V1.3.0 is affected by: Cross Site Scripting (XSS) via the i... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now