2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6969CRITICAL9.8It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an ...
CVE-2020-6174CRITICAL9.8TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
CVE-2020-8114CRITICAL9.8GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
CVE-2020-7979MEDIUM5.3GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
CVE-2020-7216HIGH7.5An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial ...
CVE-2020-8632MEDIUM5.5In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, ...
CVE-2020-8631MEDIUM5.5cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict...
CVE-2020-5237HIGH8.8Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attack...
CVE-2020-5208HIGH8.8It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a re...
CVE-2020-8615MEDIUM6.5A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves a...
CVE-2020-8517HIGH7.5An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials par...
CVE-2020-8450HIGH7.3An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer ove...
CVE-2020-8449HIGH7.5An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests ...
CVE-2020-8125CRITICAL9.8Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may re...
CVE-2020-8124MEDIUM5.3Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may all...
CVE-2020-8123MEDIUM4.9A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin ri...
CVE-2020-8122MEDIUM4.3A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share...
CVE-2020-8121HIGH8.1A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.
CVE-2020-8120MEDIUM6.1A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.
CVE-2020-8119MEDIUM4.3Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is op...
CVE-2020-8118MEDIUM5An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when...
CVE-2020-8117MEDIUM4.3Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non...
CVE-2020-8116HIGH7.3Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an ...
CVE-2020-8115MEDIUM6.1A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver ...
CVE-2020-6060HIGH7.5A stack buffer overflow vulnerability exists in the way MiniSNMPD version 1.4 handles multiple connections. A specially ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now