2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9529 | CRITICAL | 9.8 | 2.9% | Aug 10, 2020 | Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions ... |
| CVE-2020-9528 | HIGH | 7.5 | 0.8% | Aug 10, 2020 | Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions ... |
| CVE-2020-9527 | CRITICAL | 9.8 | 2.9% | Aug 10, 2020 | Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20, after 2018-08-09 through 2020), as used by many... |
| CVE-2020-9526 | MEDIUM | 5.9 | 0.6% | Aug 10, 2020 | CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure fla... |
| CVE-2020-9525 | HIGH | 8.1 | 1.6% | Aug 10, 2020 | CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that... |
| CVE-2020-8229 | MEDIUM | 5.5 | 0.5% | Aug 10, 2020 | A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system... |
| CVE-2020-8224 | HIGH | 7.8 | 0.7% | Aug 10, 2020 | A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL confi... |
| CVE-2020-6145 | HIGH | 8.8 | 1.8% | Aug 10, 2020 | An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially cr... |
| CVE-2020-6070 | HIGH | 7.8 | 1.7% | Aug 10, 2020 | An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A spec... |
| CVE-2020-13295 | HIGH | 8.8 | 1.2% | Aug 10, 2020 | For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is sus... |
| CVE-2020-13294 | MEDIUM | 5.4 | 1.2% | Aug 10, 2020 | In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application... |
| CVE-2020-13293 | HIGH | 7.1 | 1.0% | Aug 10, 2020 | In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash. |
| CVE-2020-13292 | CRITICAL | 9.6 | 1.0% | Aug 10, 2020 | In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Fl... |
| CVE-2020-4541 | MEDIUM | 6.1 | 0.7% | Aug 10, 2020 | IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2020-4539 | MEDIUM | 6.1 | 0.7% | Aug 10, 2020 | IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerabili... |
| CVE-2020-4533 | MEDIUM | 6.1 | 0.7% | Aug 10, 2020 | IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2020-12781 | HIGH | 8.8 | 0.5% | Aug 10, 2020 | Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via mal... |
| CVE-2020-12780 | HIGH | 7.5 | 1.2% | Aug 10, 2020 | A security misconfiguration exists in Combodo iTop, which can expose sensitive information. |
| CVE-2020-12779 | MEDIUM | 5.4 | 0.6% | Aug 10, 2020 | Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with maliciou... |
| CVE-2020-12778 | MEDIUM | 6.1 | 0.8% | Aug 10, 2020 | Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack. |
| CVE-2020-12777 | HIGH | 7.5 | 1.3% | Aug 10, 2020 | A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inje... |
| CVE-2020-17452 | HIGH | 7.2 | 2.4% | Aug 9, 2020 | flatCore before 1.5.7 allows upload and execution of a .php file by an admin. |
| CVE-2020-17451 | MEDIUM | 4.8 | 0.6% | Aug 9, 2020 | flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title,... |
| CVE-2020-17447 | — | — | — | Aug 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-15139. Reason: This candidate is a duplicate of ... |
| CVE-2020-16248 | MEDIUM | 5.8 | 2.7% | Aug 9, 2020 | Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this mi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now