2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10567CRITICAL9.8An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in t...
CVE-2020-10566HIGH7.8grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, mishandles font loading by a guest through a gr...
CVE-2020-10565HIGH7.8grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, does not validate the address provided as part ...
CVE-2020-10564CRITICAL9.8An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote ...
CVE-2020-5240HIGH8.5In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the...
CVE-2020-5257HIGH8.1In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard, the direction parameter was ...
CVE-2020-10563CRITICAL9.8An issue was discovered in DEVOME GRR before 3.4.1c. frmcontactlist.php mishandles a SQL query.
CVE-2020-10562HIGH7.2An issue was discovered in DEVOME GRR before 3.4.1c. admin_edit_room.php mishandles file uploads.
CVE-2020-10077CRITICAL9.8GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was cr...
CVE-2020-10076MEDIUM6.1GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge ...
CVE-2020-10075MEDIUM6.1GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or ...
CVE-2020-10074CRITICAL9.8GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be ta...
CVE-2020-10073HIGH7.5GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of servic...
CVE-2020-10218MEDIUM6.5A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter b...
CVE-2020-10092MEDIUM6.1GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to...
CVE-2020-10091MEDIUM6.1GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.
CVE-2020-10090MEDIUM5.3GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was uni...
CVE-2020-10089HIGH7.5GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,
CVE-2020-10088HIGH8.1GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited...
CVE-2020-10087HIGH7.5GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings ...
CVE-2020-10086MEDIUM5.3GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vul...
CVE-2020-10085MEDIUM5.3GitLab 12.3.5 through 12.8.1 allows Information Disclosure. A particular view was exposing merge private merge request t...
CVE-2020-10084MEDIUM5.3GitLab EE 11.6 through 12.8.1 allows Information Disclosure. Sending a specially crafted request to the vulnerability_fe...
CVE-2020-10083CRITICAL9.1GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization ch...
CVE-2020-10082MEDIUM5.3GitLab 12.2 through 12.8.1 allows Denial of Service. A denial of service vulnerability impacting the designs for public ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now