2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-23310HIGH7.5There is an Assertion 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at js-parser-statm.c:733 in...
CVE-2020-23309HIGH7.5There is an Assertion 'context_p->stack_depth == context_p->context_stack_depth' failed at js-parser-statm.c:2756 in par...
CVE-2020-23308HIGH7.5There is an Assertion 'context_p->stack_top_uint8 == LEXER_EXPRESSION_START' at js-parser-expr.c:3565 in parser_parse_ex...
CVE-2020-23306CRITICAL9.8There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0.
CVE-2020-23303CRITICAL9.8There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.
CVE-2020-23302CRITICAL9.8There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0
CVE-2020-25467MEDIUM5.5A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to caus...
CVE-2020-24671HIGH8.8Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03...
CVE-2020-24668MEDIUM5.4Trace Financial Crest Bridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03.
CVE-2020-24667HIGH8.8Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03...
CVE-2020-24663MEDIUM5.4Trace Financial CRESTBridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03.
CVE-2020-24662MEDIUM5.4SmartStream Transaction Lifecycle Management (TLM) Reconciliation Premium (RP) <3.1.0 allows XSS. This was fixed in TLM ...
CVE-2020-35452HIGH7.3Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_dige...
CVE-2020-13950HIGH7.5Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with special...
CVE-2020-13938MEDIUM5.5Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
CVE-2020-24489HIGH8.8Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of pr...
CVE-2020-24475MEDIUM5.5Improper initialization in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before v...
CVE-2020-24474HIGH8Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2...
CVE-2020-24473HIGH7.8Out of bounds write in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before versi...
CVE-2020-8704MEDIUM6.4Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially ...
CVE-2020-8703MEDIUM6.7Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 1...
CVE-2020-8702HIGH7.3Uncontrolled search path element in the Intel(R) Processor Diagnostic Tool before version 4.1.5.37 may allow an authenti...
CVE-2020-8700MEDIUM6.7Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable...
CVE-2020-8670MEDIUM6.4Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation...
CVE-2020-27383HIGH7.8Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now