2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8644 | CRITICAL | 9.8 | 86.7% | Feb 5, 2020 | PlaySMS before 1.4.3 does not sanitize inputs from a malicious string. |
| CVE-2020-8641 | HIGH | 8.8 | 10.8% | Feb 5, 2020 | Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php pa... |
| CVE-2020-6854 | MEDIUM | 5.4 | 0.5% | Feb 5, 2020 | A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attac... |
| CVE-2020-3149 | MEDIUM | 4.8 | 0.6% | Feb 5, 2020 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an au... |
| CVE-2020-3123 | HIGH | 7.5 | 2.6% | Feb 5, 2020 | A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.... |
| CVE-2020-3120 | MEDIUM | 6.5 | 2.0% | Feb 5, 2020 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco... |
| CVE-2020-3119 | HIGH | 8.8 | 5.1% | Feb 5, 2020 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, ... |
| CVE-2020-3118 | HIGH | 8.8 | 11.8% | Feb 5, 2020 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated,... |
| CVE-2020-3111 | HIGH | 8.8 | 3.1% | Feb 5, 2020 | A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, ad... |
| CVE-2020-3110 | HIGH | 8.8 | 5.7% | Feb 5, 2020 | A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras c... |
| CVE-2020-6833 | HIGH | 7.5 | 1.2% | Feb 5, 2020 | An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure... |
| CVE-2020-6754 | CRITICAL | 9.8 | 94.8% | Feb 5, 2020 | dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to ... |
| CVE-2020-8507 | HIGH | 7.5 | 1.4% | Feb 5, 2020 | The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics. |
| CVE-2020-8506 | MEDIUM | 5.3 | 1.1% | Feb 5, 2020 | The Global TV application 2.3.2 for Android and 4.7.5 for iOS sends Unencrypted Analytics. |
| CVE-2020-7978 | HIGH | 7.5 | 1.1% | Feb 5, 2020 | GitLab EE 12.6 and later through 12.7.2 allows Denial of Service. |
| CVE-2020-7977 | MEDIUM | 5.3 | 0.8% | Feb 5, 2020 | GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions. |
| CVE-2020-7976 | MEDIUM | 5.3 | 0.9% | Feb 5, 2020 | GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control. |
| CVE-2020-7974 | MEDIUM | 5.3 | 0.9% | Feb 5, 2020 | GitLab EE 10.1 through 12.7.2 allows Information Disclosure. |
| CVE-2020-7973 | MEDIUM | 6.1 | 0.9% | Feb 5, 2020 | GitLab through 12.7.2 allows XSS. |
| CVE-2020-7972 | HIGH | 7.5 | 0.9% | Feb 5, 2020 | GitLab EE 12.2 has Insecure Permissions (issue 2 of 2). |
| CVE-2020-7971 | MEDIUM | 6.1 | 0.7% | Feb 5, 2020 | GitLab EE 11.0 and later through 12.7.2 allows XSS. |
| CVE-2020-7969 | HIGH | 7.5 | 1.2% | Feb 5, 2020 | GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure. |
| CVE-2020-7968 | HIGH | 7.5 | 1.1% | Feb 5, 2020 | GitLab EE 8.0 through 12.7.2 has Incorrect Access Control. |
| CVE-2020-7967 | MEDIUM | 4.3 | 0.7% | Feb 5, 2020 | GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2). |
| CVE-2020-7966 | HIGH | 7.5 | 1.6% | Feb 5, 2020 | GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now