2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28916 | MEDIUM | 5.5 | 0.7% | Dec 4, 2020 | hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address. |
| CVE-2020-29561 | MEDIUM | 5.5 | 0.6% | Dec 4, 2020 | An issue was discovered in SonicBOOM riscv-boom 3.0.0. For LR, it does not avoid acquiring a reservation in the case whe... |
| CVE-2020-27348 | MEDIUM | 6.8 | 0.7% | Dec 4, 2020 | In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a mali... |
| CVE-2020-16123 | MEDIUM | 4.7 | 0.3% | Dec 4, 2020 | An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a cl... |
| CVE-2020-23741 | MEDIUM | 5.5 | 0.3% | Dec 3, 2020 | In AnyView (network police) network monitoring software 4.6.0.1, there is a local denial of service vulnerability in Any... |
| CVE-2020-23738 | MEDIUM | 5.5 | 0.4% | Dec 3, 2020 | There is a local denial of service vulnerability in Advanced SystemCare 13 PRO 13.5.0.174. Attackers can use a construct... |
| CVE-2020-23736 | MEDIUM | 5.5 | 0.4% | Dec 3, 2020 | There is a local denial of service vulnerability in DaDa accelerator 5.6.19.816,, attackers can use constructed programs... |
| CVE-2020-23727 | MEDIUM | 5.5 | 0.4% | Dec 3, 2020 | There is a local denial of service vulnerability in the Antiy Zhijia Terminal Defense System 5.0.2.10121559 and an attac... |
| CVE-2020-23726 | MEDIUM | 5.5 | 0.3% | Dec 3, 2020 | There is a local denial of service vulnerability in Wise Care 365 5.5.4, attackers can cause computer crash (BSOD). |
| CVE-2020-13524 | MEDIUM | 5.5 | 0.8% | Dec 3, 2020 | An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD f... |
| CVE-2020-27783 | MEDIUM | 6.1 | 3.9% | Dec 3, 2020 | A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, ... |
| CVE-2020-27762 | MEDIUM | 5.5 | 1.1% | Dec 3, 2020 | A flaw was found in ImageMagick in coders/hdr.c. An attacker who submits a crafted file that is processed by ImageMagick... |
| CVE-2020-27760 | MEDIUM | 5.5 | 1.4% | Dec 3, 2020 | In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero co... |
| CVE-2020-25711 | MEDIUM | 6.5 | 1.1% | Dec 3, 2020 | A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server... |
| CVE-2020-2323 | MEDIUM | 5.3 | 0.8% | Dec 3, 2020 | Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers w... |
| CVE-2020-28938 | MEDIUM | 5.4 | 0.5% | Dec 3, 2020 | OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application... |
| CVE-2020-14318 | MEDIUM | 4.3 | 1.5% | Dec 3, 2020 | A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to g... |
| CVE-2020-5679 | MEDIUM | 6.1 | 0.7% | Dec 3, 2020 | Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking atta... |
| CVE-2020-5678 | MEDIUM | 6.1 | 1.2% | Dec 3, 2020 | Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script... |
| CVE-2020-5677 | MEDIUM | 6.1 | 1.1% | Dec 3, 2020 | Reflected cross-site scripting vulnerability in GROWI v4.0.0 and earlier allows remote attackers to inject arbitrary scr... |
| CVE-2020-5638 | MEDIUM | 6.1 | 0.8% | Dec 3, 2020 | Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NE... |
| CVE-2020-26246 | MEDIUM | 6.5 | 0.8% | Dec 3, 2020 | Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create... |
| CVE-2020-26244 | MEDIUM | 6.8 | 0.8% | Dec 2, 2020 | Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryp... |
| CVE-2020-28206 | MEDIUM | 6.5 | 1.1% | Dec 2, 2020 | An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restri... |
| CVE-2020-13498 | MEDIUM | 5.5 | 0.9% | Dec 2, 2020 | An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially cra... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now