2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14931CRITICAL9.8A stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) 1.3a might allow remote WHOIS servers to ...
CVE-2020-13276MEDIUM4.3User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/E...
CVE-2020-13275HIGH8.1A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later ...
CVE-2020-13274HIGH7.5A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts ...
CVE-2020-13273HIGH7.5A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1
CVE-2020-13272HIGH8.8OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authoriza...
CVE-2020-13265MEDIUM5.3User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification
CVE-2020-13262MEDIUM6.1Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially craft...
CVE-2020-14930HIGH8.1An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-res...
CVE-2020-10750MEDIUM5.5Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when t...
CVE-2020-9495MEDIUM5.3Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute...
CVE-2020-14929HIGH7.5Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involvi...
CVE-2020-8167MEDIUM6.5A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong d...
CVE-2020-8165CRITICAL9.8A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attack...
CVE-2020-3972LOW3.3VMware Tools for macOS (11.x.x and prior before 11.1.1) contains a denial-of-service vulnerability in the Host-Guest Fil...
CVE-2020-13277MEDIUM6.5An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later...
CVE-2020-8184HIGH7.5A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 tha...
CVE-2020-8164HIGH7.5A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker...
CVE-2020-8162HIGH7.5A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStor...
CVE-2020-14927MEDIUM4.8Navigate CMS 2.9 allows XSS via the Alias or Real URL field of the "Web Sites > Create > Aliases > Add" screen.
CVE-2020-14926MEDIUM5.4CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.
CVE-2020-14475MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web ...
CVE-2020-13961MEDIUM6.5Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are st...
CVE-2020-4297MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerabi...
CVE-2020-4295MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerabi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now