2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29573 | HIGH | 7.5 | 2.8% | Dec 6, 2020 | sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer ov... |
| CVE-2020-28950 | HIGH | 7.8 | 0.5% | Dec 4, 2020 | The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attac... |
| CVE-2020-25465 | HIGH | 7.5 | 1.6% | Dec 4, 2020 | Null Pointer Dereference. in xObjectBindingFromExpression at moddable/xs/sources/xsSyntaxical.c:3419 in Moddable SDK bef... |
| CVE-2020-25464 | HIGH | 7.5 | 1.1% | Dec 4, 2020 | Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is onl... |
| CVE-2020-25463 | HIGH | 7.5 | 1.3% | Dec 4, 2020 | Invalid Memory Access in fxUTF8Decode at moddable/xs/sources/xsCommon.c:916 in Moddable SDK before OS200908 causes a den... |
| CVE-2020-25461 | HIGH | 7.5 | 1.3% | Dec 4, 2020 | Invalid Memory Access in the fxProxyGetter function in moddable/xs/sources/xsProxy.c in Moddable SDK before OS200908 cau... |
| CVE-2020-27408 | HIGH | 7.5 | 1.7% | Dec 4, 2020 | OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow... |
| CVE-2020-27766 | HIGH | 7.8 | 1.2% | Dec 4, 2020 | A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by I... |
| CVE-2020-5675 | HIGH | 7.5 | 2.8% | Dec 4, 2020 | Out-of-bounds read vulnerability in GT21 model of GOT2000 series (GT2107-WTBD V01.39.000 and earlier, GT2107-WTSD V01.39... |
| CVE-2020-26248 | HIGH | 8.2 | 12.4% | Dec 3, 2020 | In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve d... |
| CVE-2020-29534 | HIGH | 7.8 | 0.5% | Dec 3, 2020 | An issue was discovered in the Linux kernel before 5.9.3. io_uring takes a non-refcounted reference to the files_struct ... |
| CVE-2020-29529 | HIGH | 7.5 | 2.8% | Dec 3, 2020 | HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protec... |
| CVE-2020-23740 | HIGH | 7.8 | 0.3% | Dec 3, 2020 | In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use... |
| CVE-2020-17527 | HIGH | 7.5 | 24.6% | Dec 3, 2020 | While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 ... |
| CVE-2020-28175 | HIGH | 7.8 | 0.5% | Dec 3, 2020 | There is a local privilege escalation vulnerability in Alfredo Milani Comparetti SpeedFan 4.52. Attackers can use constr... |
| CVE-2020-13525 | HIGH | 8.8 | 1.7% | Dec 3, 2020 | The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL i... |
| CVE-2020-28251 | HIGH | 8.1 | 1.2% | Dec 3, 2020 | NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be... |
| CVE-2020-27778 | HIGH | 7.5 | 2.2% | Dec 3, 2020 | A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this ... |
| CVE-2020-25693 | HIGH | 8.1 | 1.5% | Dec 3, 2020 | A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() ca... |
| CVE-2020-25649 | HIGH | 7.5 | 17.6% | Dec 3, 2020 | A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allow... |
| CVE-2020-23735 | HIGH | 7.8 | 0.3% | Dec 3, 2020 | In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability. Attackers can use the constru... |
| CVE-2020-14381 | HIGH | 7.8 | 0.8% | Dec 3, 2020 | A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory ... |
| CVE-2020-14351 | HIGH | 7.8 | 0.3% | Dec 3, 2020 | A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local atta... |
| CVE-2020-14339 | HIGH | 8.8 | 0.4% | Dec 3, 2020 | A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This fil... |
| CVE-2020-13584 | HIGH | 8.8 | 4.4% | Dec 3, 2020 | An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now