2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6969 | CRITICAL | 9.8 | 2.2% | Feb 5, 2020 | It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an ... |
| CVE-2020-6174 | CRITICAL | 9.8 | 1.0% | Feb 5, 2020 | TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature. |
| CVE-2020-8114 | CRITICAL | 9.8 | 1.4% | Feb 5, 2020 | GitLab EE 8.9 and later through 12.7.2 has Insecure Permission |
| CVE-2020-7979 | MEDIUM | 5.3 | 0.9% | Feb 5, 2020 | GitLab EE 8.9 and later through 12.7.2 has Insecure Permission |
| CVE-2020-7216 | HIGH | 7.5 | 1.1% | Feb 5, 2020 | An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial ... |
| CVE-2020-8632 | MEDIUM | 5.5 | 0.4% | Feb 5, 2020 | In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, ... |
| CVE-2020-8631 | MEDIUM | 5.5 | 0.4% | Feb 5, 2020 | cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict... |
| CVE-2020-5237 | HIGH | 8.8 | 3.9% | Feb 5, 2020 | Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attack... |
| CVE-2020-5208 | HIGH | 8.8 | 3.3% | Feb 5, 2020 | It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a re... |
| CVE-2020-8615 | MEDIUM | 6.5 | 8.8% | Feb 4, 2020 | A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves a... |
| CVE-2020-8517 | HIGH | 7.5 | 6.8% | Feb 4, 2020 | An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials par... |
| CVE-2020-8450 | HIGH | 7.3 | 71.8% | Feb 4, 2020 | An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer ove... |
| CVE-2020-8449 | HIGH | 7.5 | 8.3% | Feb 4, 2020 | An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests ... |
| CVE-2020-8125 | CRITICAL | 9.8 | 4.1% | Feb 4, 2020 | Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may re... |
| CVE-2020-8124 | MEDIUM | 5.3 | 1.7% | Feb 4, 2020 | Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may all... |
| CVE-2020-8123 | MEDIUM | 4.9 | 1.1% | Feb 4, 2020 | A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin ri... |
| CVE-2020-8122 | MEDIUM | 4.3 | 0.7% | Feb 4, 2020 | A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share... |
| CVE-2020-8121 | HIGH | 8.1 | 1.0% | Feb 4, 2020 | A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer. |
| CVE-2020-8120 | MEDIUM | 6.1 | 0.9% | Feb 4, 2020 | A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation. |
| CVE-2020-8119 | MEDIUM | 4.3 | 0.9% | Feb 4, 2020 | Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is op... |
| CVE-2020-8118 | MEDIUM | 5 | 1.3% | Feb 4, 2020 | An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when... |
| CVE-2020-8117 | MEDIUM | 4.3 | 0.7% | Feb 4, 2020 | Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non... |
| CVE-2020-8116 | HIGH | 7.3 | 3.1% | Feb 4, 2020 | Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an ... |
| CVE-2020-8115 | MEDIUM | 6.1 | 7.1% | Feb 4, 2020 | A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver ... |
| CVE-2020-6060 | HIGH | 7.5 | 2.2% | Feb 4, 2020 | A stack buffer overflow vulnerability exists in the way MiniSNMPD version 1.4 handles multiple connections. A specially ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now