2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-16591MEDIUM5.5A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read...
CVE-2020-16590MEDIUM5.5A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_...
CVE-2020-16589MEDIUM5.5A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile....
CVE-2020-16588MEDIUM5.5A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp...
CVE-2020-16587MEDIUM5.5A heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruct...
CVE-2020-26257MEDIUM6.5Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation...
CVE-2020-2020MEDIUM5.5An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows us...
CVE-2020-7776MEDIUM6.4This affects the package phpoffice/phpspreadsheet from 0.0.0. The library is vulnerable to XSS when creating an html out...
CVE-2020-29660MEDIUM4.4A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io...
CVE-2020-26836MEDIUM6.1SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to...
CVE-2020-26835MEDIUM6.1SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attack...
CVE-2020-26834MEDIUM5.4SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user ...
CVE-2020-26828MEDIUM6.4SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of ...
CVE-2020-26826MEDIUM6.5Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any f...
CVE-2020-26816MEDIUM4.5SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is st...
CVE-2020-26260MEDIUM6.4BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a ...
CVE-2020-7337MEDIUM6.7Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Pa...
CVE-2020-27349MEDIUM5.5Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This a...
CVE-2020-26967MEDIUM6.5When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into in...
CVE-2020-26966MEDIUM6.5Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a ...
CVE-2020-26965MEDIUM6.5Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field,...
CVE-2020-26964MEDIUM6.8If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, u...
CVE-2020-26963MEDIUM4.3Repeated calls to the history and location interfaces could have been used to hang the browser. This was addressed by in...
CVE-2020-26962MEDIUM6.1Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated...
CVE-2020-26961MEDIUM6.5When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now