2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12464MEDIUM6.7usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occ...
CVE-2020-11021HIGH7.5Actions Http-Client (NPM @actions/http-client) before version 1.0.8 can disclose Authorization headers to incorrect doma...
CVE-2020-11020CRITICAL9.8Faye (NPM, RubyGem) versions greater than 0.5.0 and before 1.0.4, 1.1.3 and 1.2.5, has the potential for authentication ...
CVE-2020-12462MEDIUM6.1The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
CVE-2020-12461HIGH8.8PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can d...
CVE-2020-12277MEDIUM5.3GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activ...
CVE-2020-12276MEDIUM4.8GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature.
CVE-2020-12275MEDIUM5.3GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snipp...
CVE-2020-11009MEDIUM6.5In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job de...
CVE-2020-8775HIGH8.9Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.
CVE-2020-12459MEDIUM5.5In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/gra...
CVE-2020-12458MEDIUM5.5An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database ...
CVE-2020-8774HIGH8.8Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID"...
CVE-2020-8773HIGH8.9The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.
CVE-2020-7804HIGH7.2ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary ...
CVE-2020-2575HIGH7.5Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar...
CVE-2020-12446HIGH7.8The ene.sys driver in G.SKILL Trident Z Lighting Control through 1.00.08 exposes mapping and un-mapping of physical memo...
CVE-2020-12252MEDIUM6.2An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an au...
CVE-2020-12251LOW2.2An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an authenticated user to change th...
CVE-2020-11677HIGH8.8Cerner medico 26.00 has a Local Buffer Overflow (issue 3 of 3).
CVE-2020-11676HIGH8.8Cerner medico 26.00 has a Local Buffer Overflow (issue 2 of 3).
CVE-2020-11675HIGH8.8Cerner medico 26.00 has a Local Buffer Overflow (issue 1 of 3).
CVE-2020-11674HIGH8.8Cerner medico 26.00 allows variable reuse, possibly causing data corruption.
CVE-2020-11446HIGH7.8ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard l...
CVE-2020-10797MEDIUM6.1An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After pass...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now