2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10081 | MEDIUM | 6.5 | 0.9% | Mar 13, 2020 | GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potent... |
| CVE-2020-10080 | MEDIUM | 5.3 | 0.9% | Mar 13, 2020 | GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribut... |
| CVE-2020-10079 | MEDIUM | 5.3 | 0.9% | Mar 13, 2020 | GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required ... |
| CVE-2020-10078 | MEDIUM | 6.1 | 0.7% | Mar 13, 2020 | GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scri... |
| CVE-2020-8571 | HIGH | 7.5 | 1.8% | Mar 13, 2020 | StorageGRID (formerly StorageGRID Webscale) versions 10.0.0 through 11.3 prior to 11.2.0.8 and 11.3.0.4 are susceptible ... |
| CVE-2020-10196 | MEDIUM | 6.1 | 1.4% | Mar 13, 2020 | An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary... |
| CVE-2020-10195 | MEDIUM | 6.3 | 1.1% | Mar 13, 2020 | The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to... |
| CVE-2020-1953 | CRITICAL | 10 | 6.7% | Mar 13, 2020 | Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of... |
| CVE-2020-10544 | MEDIUM | 6.1 | 0.8% | Mar 13, 2020 | An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, ... |
| CVE-2020-10541 | CRITICAL | 9.8 | 10.1% | Mar 13, 2020 | Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1... |
| CVE-2020-10540 | HIGH | 8.8 | 0.5% | Mar 13, 2020 | Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules. |
| CVE-2020-1887 | CRITICAL | 9.1 | 1.3% | Mar 13, 2020 | Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to... |
| CVE-2020-8469 | HIGH | 7.8 | 0.5% | Mar 12, 2020 | Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentiall... |
| CVE-2020-7600 | MEDIUM | 5.3 | 1.1% | Mar 12, 2020 | querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name... |
| CVE-2020-1863 | HIGH | 7.5 | 0.9% | Mar 12, 2020 | Huawei USG6000V with versions V500R001C20SPC300, V500R003C00SPC100, and V500R005C00SPC100 have an out-of-bounds read vul... |
| CVE-2020-10535 | MEDIUM | 5.3 | 1.0% | Mar 12, 2020 | GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within... |
| CVE-2020-10534 | CRITICAL | 9.8 | 1.2% | Mar 12, 2020 | In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation ... |
| CVE-2020-9064 | MEDIUM | 5.5 | 0.2% | Mar 12, 2020 | Huawei smartphone Honor V30 with versions earlier than OxfordS-AN00A 10.0.1.167(C00E166R4P1) have an improper authentica... |
| CVE-2020-6643 | MEDIUM | 5.4 | 0.8% | Mar 12, 2020 | An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows ... |
| CVE-2020-0583 | HIGH | 8.8 | 0.4% | Mar 12, 2020 | Improper access control in the subsystem for Intel(R) Smart Sound Technology may allow an authenticated user to potentia... |
| CVE-2020-0551 | MEDIUM | 5.6 | 1.0% | Mar 12, 2020 | Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to pote... |
| CVE-2020-0550 | MEDIUM | 5.6 | 0.3% | Mar 12, 2020 | Improper data forwarding in some data cache for some Intel(R) Processors may allow an authenticated user to potentially ... |
| CVE-2020-0574 | MEDIUM | 5.9 | 0.4% | Mar 12, 2020 | Improper configuration in block design for Intel(R) MAX(R) 10 FPGA all versions may allow an authenticated user to poten... |
| CVE-2020-0567 | MEDIUM | 5.5 | 0.3% | Mar 12, 2020 | Improper input validation in Intel(R) Graphics Drivers before version 26.20.100.7212 may allow an authenticated user to ... |
| CVE-2020-0565 | HIGH | 7.8 | 0.3% | Mar 12, 2020 | Uncontrolled search path in Intel(R) Graphics Drivers before version 26.20.100.7158 may allow an authenticated user to p... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now