2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27174 | HIGH | 7.5 | 1.7% | Oct 16, 2020 | In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage w... |
| CVE-2020-27173 | HIGH | 7.5 | 1.5% | Oct 16, 2020 | In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input so... |
| CVE-2020-7591 | HIGH | 8.8 | 1.5% | Oct 15, 2020 | A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow a... |
| CVE-2020-12503 | HIGH | 7.2 | 23.3% | Oct 15, 2020 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv... |
| CVE-2020-12502 | HIGH | 8.8 | 1.0% | Oct 15, 2020 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv... |
| CVE-2020-25858 | HIGH | 7.5 | 9.6% | Oct 15, 2020 | The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not val... |
| CVE-2020-11637 | HIGH | 7.5 | 1.1% | Oct 15, 2020 | A memory leak in the TFTP service in B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53, <D4.63, <A4.73 and ... |
| CVE-2020-6108 | HIGH | 7.8 | 2.1% | Oct 15, 2020 | An exploitable code execution vulnerability exists in the fsck_chk_orphan_node functionality of F2fs-Tools F2fs.Fsck 1.1... |
| CVE-2020-6105 | HIGH | 7.8 | 2.0% | Oct 15, 2020 | An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A... |
| CVE-2020-7334 | HIGH | 8.2 | 0.3% | Oct 15, 2020 | Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2... |
| CVE-2020-27157 | HIGH | 8.1 | 1.0% | Oct 15, 2020 | Veritas APTARE versions prior to 10.5 included code that bypassed the normal login process when specific authentication ... |
| CVE-2020-5642 | HIGH | 8.8 | 0.8% | Oct 15, 2020 | Cross-site request forgery (CSRF) vulnerability in Live Chat - Live support version 3.1.0 and earlier allows remote atta... |
| CVE-2020-27153 | HIGH | 8.6 | 4.1% | Oct 15, 2020 | In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attack... |
| CVE-2020-6374 | HIGH | 7.8 | 1.2% | Oct 15, 2020 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received ... |
| CVE-2020-6373 | HIGH | 7.8 | 1.2% | Oct 15, 2020 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources... |
| CVE-2020-6372 | HIGH | 7.8 | 1.2% | Oct 15, 2020 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources... |
| CVE-2020-8350 | HIGH | 8.8 | 0.6% | Oct 14, 2020 | An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 th... |
| CVE-2020-8345 | HIGH | 7.8 | 0.4% | Oct 14, 2020 | A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feat... |
| CVE-2020-8338 | HIGH | 7.8 | 0.4% | Oct 14, 2020 | A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with ... |
| CVE-2020-7383 | HIGH | 8.1 | 1.1% | Oct 14, 2020 | A SQL Injection issue in Rapid7 Nexpose version prior to 6.6.49 that may have allowed an authenticated user with a low p... |
| CVE-2020-3427 | HIGH | 7.8 | 0.3% | Oct 14, 2020 | The Windows Logon installer prior to 4.1.2 did not properly validate file installation paths. This allows an attacker wi... |
| CVE-2020-9746 | HIGH | 8.8 | 4.2% | Oct 14, 2020 | Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerabilit... |
| CVE-2020-0423 | HIGH | 7.8 | 0.5% | Oct 14, 2020 | In binder_release_work of binder.c, there is a possible use-after-free due to improper locking. This could lead to local... |
| CVE-2020-0421 | HIGH | 7.8 | 0.3% | Oct 14, 2020 | In appendFormatV of String8.cpp, there is a possible out of bounds write due to incorrect error handling. This could lea... |
| CVE-2020-0420 | HIGH | 7.8 | 0.1% | Oct 14, 2020 | In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. Th... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now