2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-29573HIGH7.5sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer ov...
CVE-2020-28950HIGH7.8The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attac...
CVE-2020-25465HIGH7.5Null Pointer Dereference. in xObjectBindingFromExpression at moddable/xs/sources/xsSyntaxical.c:3419 in Moddable SDK bef...
CVE-2020-25464HIGH7.5Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is onl...
CVE-2020-25463HIGH7.5Invalid Memory Access in fxUTF8Decode at moddable/xs/sources/xsCommon.c:916 in Moddable SDK before OS200908 causes a den...
CVE-2020-25461HIGH7.5Invalid Memory Access in the fxProxyGetter function in moddable/xs/sources/xsProxy.c in Moddable SDK before OS200908 cau...
CVE-2020-27408HIGH7.5OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow...
CVE-2020-27766HIGH7.8A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by I...
CVE-2020-5675HIGH7.5Out-of-bounds read vulnerability in GT21 model of GOT2000 series (GT2107-WTBD V01.39.000 and earlier, GT2107-WTSD V01.39...
CVE-2020-26248HIGH8.2In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve d...
CVE-2020-29534HIGH7.8An issue was discovered in the Linux kernel before 5.9.3. io_uring takes a non-refcounted reference to the files_struct ...
CVE-2020-29529HIGH7.5HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protec...
CVE-2020-23740HIGH7.8In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use...
CVE-2020-17527HIGH7.5While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 ...
CVE-2020-28175HIGH7.8There is a local privilege escalation vulnerability in Alfredo Milani Comparetti SpeedFan 4.52. Attackers can use constr...
CVE-2020-13525HIGH8.8The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL i...
CVE-2020-28251HIGH8.1NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be...
CVE-2020-27778HIGH7.5A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this ...
CVE-2020-25693HIGH8.1A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() ca...
CVE-2020-25649HIGH7.5A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allow...
CVE-2020-23735HIGH7.8In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability. Attackers can use the constru...
CVE-2020-14381HIGH7.8A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory ...
CVE-2020-14351HIGH7.8A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local atta...
CVE-2020-14339HIGH8.8A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This fil...
CVE-2020-13584HIGH8.8An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now