2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-16591 | MEDIUM | 5.5 | 0.9% | Dec 9, 2020 | A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read... |
| CVE-2020-16590 | MEDIUM | 5.5 | 0.9% | Dec 9, 2020 | A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_... |
| CVE-2020-16589 | MEDIUM | 5.5 | 1.1% | Dec 9, 2020 | A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile.... |
| CVE-2020-16588 | MEDIUM | 5.5 | 1.2% | Dec 9, 2020 | A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp... |
| CVE-2020-16587 | MEDIUM | 5.5 | 1.2% | Dec 9, 2020 | A heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruct... |
| CVE-2020-26257 | MEDIUM | 6.5 | 2.4% | Dec 9, 2020 | Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation... |
| CVE-2020-2020 | MEDIUM | 5.5 | 0.3% | Dec 9, 2020 | An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows us... |
| CVE-2020-7776 | MEDIUM | 6.4 | 1.3% | Dec 9, 2020 | This affects the package phpoffice/phpspreadsheet from 0.0.0. The library is vulnerable to XSS when creating an html out... |
| CVE-2020-29660 | MEDIUM | 4.4 | 0.5% | Dec 9, 2020 | A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io... |
| CVE-2020-26836 | MEDIUM | 6.1 | 2.3% | Dec 9, 2020 | SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to... |
| CVE-2020-26835 | MEDIUM | 6.1 | 0.8% | Dec 9, 2020 | SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attack... |
| CVE-2020-26834 | MEDIUM | 5.4 | 0.7% | Dec 9, 2020 | SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user ... |
| CVE-2020-26828 | MEDIUM | 6.4 | 0.8% | Dec 9, 2020 | SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of ... |
| CVE-2020-26826 | MEDIUM | 6.5 | 1.2% | Dec 9, 2020 | Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any f... |
| CVE-2020-26816 | MEDIUM | 4.5 | 0.2% | Dec 9, 2020 | SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is st... |
| CVE-2020-26260 | MEDIUM | 6.4 | 0.8% | Dec 9, 2020 | BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a ... |
| CVE-2020-7337 | MEDIUM | 6.7 | 0.4% | Dec 9, 2020 | Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Pa... |
| CVE-2020-27349 | MEDIUM | 5.5 | 0.3% | Dec 9, 2020 | Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This a... |
| CVE-2020-26967 | MEDIUM | 6.5 | 0.8% | Dec 9, 2020 | When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into in... |
| CVE-2020-26966 | MEDIUM | 6.5 | 1.3% | Dec 9, 2020 | Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a ... |
| CVE-2020-26965 | MEDIUM | 6.5 | 1.2% | Dec 9, 2020 | Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field,... |
| CVE-2020-26964 | MEDIUM | 6.8 | 0.9% | Dec 9, 2020 | If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, u... |
| CVE-2020-26963 | MEDIUM | 4.3 | 0.8% | Dec 9, 2020 | Repeated calls to the history and location interfaces could have been used to hang the browser. This was addressed by in... |
| CVE-2020-26962 | MEDIUM | 6.1 | 0.7% | Dec 9, 2020 | Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated... |
| CVE-2020-26961 | MEDIUM | 6.5 | 1.2% | Dec 9, 2020 | When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now