2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-27174HIGH7.5In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage w...
CVE-2020-27173HIGH7.5In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input so...
CVE-2020-7591HIGH8.8A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow a...
CVE-2020-12503HIGH7.2Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv...
CVE-2020-12502HIGH8.8Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv...
CVE-2020-25858HIGH7.5The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not val...
CVE-2020-11637HIGH7.5A memory leak in the TFTP service in B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53, <D4.63, <A4.73 and ...
CVE-2020-6108HIGH7.8An exploitable code execution vulnerability exists in the fsck_chk_orphan_node functionality of F2fs-Tools F2fs.Fsck 1.1...
CVE-2020-6105HIGH7.8An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A...
CVE-2020-7334HIGH8.2Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2...
CVE-2020-27157HIGH8.1Veritas APTARE versions prior to 10.5 included code that bypassed the normal login process when specific authentication ...
CVE-2020-5642HIGH8.8Cross-site request forgery (CSRF) vulnerability in Live Chat - Live support version 3.1.0 and earlier allows remote atta...
CVE-2020-27153HIGH8.6In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attack...
CVE-2020-6374HIGH7.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received ...
CVE-2020-6373HIGH7.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources...
CVE-2020-6372HIGH7.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources...
CVE-2020-8350HIGH8.8An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 th...
CVE-2020-8345HIGH7.8A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feat...
CVE-2020-8338HIGH7.8A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with ...
CVE-2020-7383HIGH8.1A SQL Injection issue in Rapid7 Nexpose version prior to 6.6.49 that may have allowed an authenticated user with a low p...
CVE-2020-3427HIGH7.8The Windows Logon installer prior to 4.1.2 did not properly validate file installation paths. This allows an attacker wi...
CVE-2020-9746HIGH8.8Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerabilit...
CVE-2020-0423HIGH7.8In binder_release_work of binder.c, there is a possible use-after-free due to improper locking. This could lead to local...
CVE-2020-0421HIGH7.8In appendFormatV of String8.cpp, there is a possible out of bounds write due to incorrect error handling. This could lea...
CVE-2020-0420HIGH7.8In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. Th...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now