2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8644CRITICAL9.8PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
CVE-2020-8641HIGH8.8Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php pa...
CVE-2020-6854MEDIUM5.4A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attac...
CVE-2020-3149MEDIUM4.8A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an au...
CVE-2020-3123HIGH7.5A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102....
CVE-2020-3120MEDIUM6.5A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco...
CVE-2020-3119HIGH8.8A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, ...
CVE-2020-3118HIGH8.8A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated,...
CVE-2020-3111HIGH8.8A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, ad...
CVE-2020-3110HIGH8.8A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras c...
CVE-2020-6833HIGH7.5An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure...
CVE-2020-6754CRITICAL9.8dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to ...
CVE-2020-8507HIGH7.5The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics.
CVE-2020-8506MEDIUM5.3The Global TV application 2.3.2 for Android and 4.7.5 for iOS sends Unencrypted Analytics.
CVE-2020-7978HIGH7.5GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.
CVE-2020-7977MEDIUM5.3GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.
CVE-2020-7976MEDIUM5.3GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.
CVE-2020-7974MEDIUM5.3GitLab EE 10.1 through 12.7.2 allows Information Disclosure.
CVE-2020-7973MEDIUM6.1GitLab through 12.7.2 allows XSS.
CVE-2020-7972HIGH7.5GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
CVE-2020-7971MEDIUM6.1GitLab EE 11.0 and later through 12.7.2 allows XSS.
CVE-2020-7969HIGH7.5GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.
CVE-2020-7968HIGH7.5GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
CVE-2020-7967MEDIUM4.3GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).
CVE-2020-7966HIGH7.5GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now