2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10081MEDIUM6.5GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potent...
CVE-2020-10080MEDIUM5.3GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribut...
CVE-2020-10079MEDIUM5.3GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required ...
CVE-2020-10078MEDIUM6.1GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scri...
CVE-2020-8571HIGH7.5StorageGRID (formerly StorageGRID Webscale) versions 10.0.0 through 11.3 prior to 11.2.0.8 and 11.3.0.4 are susceptible ...
CVE-2020-10196MEDIUM6.1An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary...
CVE-2020-10195MEDIUM6.3The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to...
CVE-2020-1953CRITICAL10Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of...
CVE-2020-10544MEDIUM6.1An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, ...
CVE-2020-10541CRITICAL9.8Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1...
CVE-2020-10540HIGH8.8Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.
CVE-2020-1887CRITICAL9.1Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to...
CVE-2020-8469HIGH7.8Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentiall...
CVE-2020-7600MEDIUM5.3querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name...
CVE-2020-1863HIGH7.5Huawei USG6000V with versions V500R001C20SPC300, V500R003C00SPC100, and V500R005C00SPC100 have an out-of-bounds read vul...
CVE-2020-10535MEDIUM5.3GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within...
CVE-2020-10534CRITICAL9.8In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation ...
CVE-2020-9064MEDIUM5.5Huawei smartphone Honor V30 with versions earlier than OxfordS-AN00A 10.0.1.167(C00E166R4P1) have an improper authentica...
CVE-2020-6643MEDIUM5.4An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows ...
CVE-2020-0583HIGH8.8Improper access control in the subsystem for Intel(R) Smart Sound Technology may allow an authenticated user to potentia...
CVE-2020-0551MEDIUM5.6Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to pote...
CVE-2020-0550MEDIUM5.6Improper data forwarding in some data cache for some Intel(R) Processors may allow an authenticated user to potentially ...
CVE-2020-0574MEDIUM5.9Improper configuration in block design for Intel(R) MAX(R) 10 FPGA all versions may allow an authenticated user to poten...
CVE-2020-0567MEDIUM5.5Improper input validation in Intel(R) Graphics Drivers before version 26.20.100.7212 may allow an authenticated user to ...
CVE-2020-0565HIGH7.8Uncontrolled search path in Intel(R) Graphics Drivers before version 26.20.100.7158 may allow an authenticated user to p...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now