2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9529CRITICAL9.8Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions ...
CVE-2020-9528HIGH7.5Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions ...
CVE-2020-9527CRITICAL9.8Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20, after 2018-08-09 through 2020), as used by many...
CVE-2020-9526MEDIUM5.9CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure fla...
CVE-2020-9525HIGH8.1CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that...
CVE-2020-8229MEDIUM5.5A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system...
CVE-2020-8224HIGH7.8A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL confi...
CVE-2020-6145HIGH8.8An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially cr...
CVE-2020-6070HIGH7.8An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A spec...
CVE-2020-13295HIGH8.8For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is sus...
CVE-2020-13294MEDIUM5.4In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application...
CVE-2020-13293HIGH7.1In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
CVE-2020-13292CRITICAL9.6In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Fl...
CVE-2020-4541MEDIUM6.1IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2020-4539MEDIUM6.1IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerabili...
CVE-2020-4533MEDIUM6.1IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2020-12781HIGH8.8Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via mal...
CVE-2020-12780HIGH7.5A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
CVE-2020-12779MEDIUM5.4Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with maliciou...
CVE-2020-12778MEDIUM6.1Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.
CVE-2020-12777HIGH7.5A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inje...
CVE-2020-17452HIGH7.2flatCore before 1.5.7 allows upload and execution of a .php file by an admin.
CVE-2020-17451MEDIUM4.8flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title,...
CVE-2020-17447Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-15139. Reason: This candidate is a duplicate of ...
CVE-2020-16248MEDIUM5.8Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this mi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now