2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36429MEDIUM5.5Variant_encodeJson in open62541 1.x before 1.0.4 has an out-of-bounds write for a large recursion depth.
CVE-2020-36428HIGH8.8matio (aka MAT File I/O Library) 1.5.18 through 1.5.21 has a heap-based buffer overflow in ReadInt32DataDouble (called f...
CVE-2020-5349CRITICAL9.8Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential v...
CVE-2020-5323HIGH8.1Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1...
CVE-2020-5322CRITICAL9.1Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a command injection vulnerability. A re...
CVE-2020-5321HIGH7.6Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1...
CVE-2020-5320HIGH7.2Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1...
CVE-2020-5315HIGH8.8Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user pa...
CVE-2020-29503MEDIUM4.4Dell EMC PowerStore versions prior to 1.0.3.0.5.xxx contain a file permission Vulnerability. A locally authenticated att...
CVE-2020-29499MEDIUM6.7Dell EMC PowerStore versions prior to 1.0.3.0.5.006 contain an OS Command Injection vulnerability in PowerStore X enviro...
CVE-2020-22741HIGH7.5An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after ...
CVE-2020-20249MEDIUM6.5Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending ...
CVE-2020-20248MEDIUM6.5Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authen...
CVE-2020-36427MEDIUM5.5GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image.
CVE-2020-36426HIGH7.5An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).
CVE-2020-36425MEDIUM5.3An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether ...
CVE-2020-36424MEDIUM4.7An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-H...
CVE-2020-36423HIGH7.5An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 1...
CVE-2020-36422MEDIUM5.3An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to ...
CVE-2020-36421MEDIUM5.3An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA priva...
CVE-2020-22650HIGH7.5A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system cras...
CVE-2020-20230MEDIUM6.5Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authentic...
CVE-2020-5031MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2020-4980MEDIUM6.5IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host conn...
CVE-2020-4821CRITICAL9.8IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configuration...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now