2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14931 | CRITICAL | 9.8 | 2.6% | Jun 19, 2020 | A stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) 1.3a might allow remote WHOIS servers to ... |
| CVE-2020-13276 | MEDIUM | 4.3 | 0.7% | Jun 19, 2020 | User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/E... |
| CVE-2020-13275 | HIGH | 8.1 | 1.0% | Jun 19, 2020 | A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later ... |
| CVE-2020-13274 | HIGH | 7.5 | 1.1% | Jun 19, 2020 | A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts ... |
| CVE-2020-13273 | HIGH | 7.5 | 1.2% | Jun 19, 2020 | A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1 |
| CVE-2020-13272 | HIGH | 8.8 | 0.6% | Jun 19, 2020 | OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authoriza... |
| CVE-2020-13265 | MEDIUM | 5.3 | 0.7% | Jun 19, 2020 | User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification |
| CVE-2020-13262 | MEDIUM | 6.1 | 0.9% | Jun 19, 2020 | Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially craft... |
| CVE-2020-14930 | HIGH | 8.1 | 3.4% | Jun 19, 2020 | An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-res... |
| CVE-2020-10750 | MEDIUM | 5.5 | 0.4% | Jun 19, 2020 | Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when t... |
| CVE-2020-9495 | MEDIUM | 5.3 | 8.0% | Jun 19, 2020 | Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute... |
| CVE-2020-14929 | HIGH | 7.5 | 1.8% | Jun 19, 2020 | Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involvi... |
| CVE-2020-8167 | MEDIUM | 6.5 | 1.5% | Jun 19, 2020 | A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong d... |
| CVE-2020-8165 | CRITICAL | 9.8 | 45.7% | Jun 19, 2020 | A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attack... |
| CVE-2020-3972 | LOW | 3.3 | 0.4% | Jun 19, 2020 | VMware Tools for macOS (11.x.x and prior before 11.1.1) contains a denial-of-service vulnerability in the Host-Guest Fil... |
| CVE-2020-13277 | MEDIUM | 6.5 | 1.8% | Jun 19, 2020 | An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later... |
| CVE-2020-8184 | HIGH | 7.5 | 2.9% | Jun 19, 2020 | A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 tha... |
| CVE-2020-8164 | HIGH | 7.5 | 4.2% | Jun 19, 2020 | A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker... |
| CVE-2020-8162 | HIGH | 7.5 | 3.1% | Jun 19, 2020 | A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStor... |
| CVE-2020-14927 | MEDIUM | 4.8 | 0.5% | Jun 19, 2020 | Navigate CMS 2.9 allows XSS via the Alias or Real URL field of the "Web Sites > Create > Aliases > Add" screen. |
| CVE-2020-14926 | MEDIUM | 5.4 | 0.6% | Jun 19, 2020 | CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page. |
| CVE-2020-14475 | MEDIUM | 6.1 | 0.8% | Jun 19, 2020 | A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web ... |
| CVE-2020-13961 | MEDIUM | 6.5 | 1.7% | Jun 19, 2020 | Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are st... |
| CVE-2020-4297 | MEDIUM | 5.4 | 0.6% | Jun 19, 2020 | IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerabi... |
| CVE-2020-4295 | MEDIUM | 5.4 | 0.6% | Jun 19, 2020 | IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerabi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now