2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-28916MEDIUM5.5hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
CVE-2020-29561MEDIUM5.5An issue was discovered in SonicBOOM riscv-boom 3.0.0. For LR, it does not avoid acquiring a reservation in the case whe...
CVE-2020-27348MEDIUM6.8In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a mali...
CVE-2020-16123MEDIUM4.7An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a cl...
CVE-2020-23741MEDIUM5.5In AnyView (network police) network monitoring software 4.6.0.1, there is a local denial of service vulnerability in Any...
CVE-2020-23738MEDIUM5.5There is a local denial of service vulnerability in Advanced SystemCare 13 PRO 13.5.0.174. Attackers can use a construct...
CVE-2020-23736MEDIUM5.5There is a local denial of service vulnerability in DaDa accelerator 5.6.19.816,, attackers can use constructed programs...
CVE-2020-23727MEDIUM5.5There is a local denial of service vulnerability in the Antiy Zhijia Terminal Defense System 5.0.2.10121559 and an attac...
CVE-2020-23726MEDIUM5.5There is a local denial of service vulnerability in Wise Care 365 5.5.4, attackers can cause computer crash (BSOD).
CVE-2020-13524MEDIUM5.5An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD f...
CVE-2020-27783MEDIUM6.1A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, ...
CVE-2020-27762MEDIUM5.5A flaw was found in ImageMagick in coders/hdr.c. An attacker who submits a crafted file that is processed by ImageMagick...
CVE-2020-27760MEDIUM5.5In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero co...
CVE-2020-25711MEDIUM6.5A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server...
CVE-2020-2323MEDIUM5.3Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers w...
CVE-2020-28938MEDIUM5.4OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application...
CVE-2020-14318MEDIUM4.3A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to g...
CVE-2020-5679MEDIUM6.1Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking atta...
CVE-2020-5678MEDIUM6.1Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script...
CVE-2020-5677MEDIUM6.1Reflected cross-site scripting vulnerability in GROWI v4.0.0 and earlier allows remote attackers to inject arbitrary scr...
CVE-2020-5638MEDIUM6.1Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NE...
CVE-2020-26246MEDIUM6.5Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create...
CVE-2020-26244MEDIUM6.8Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryp...
CVE-2020-28206MEDIUM6.5An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restri...
CVE-2020-13498MEDIUM5.5An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially cra...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now