2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-22040MEDIUM6.5A Denial of Service vulnerability exists in FFmpeg 4.2 idue to a memory leak in the v_frame_alloc function in frame.c.
CVE-2020-22039MEDIUM6.5A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the inavi_add_ientry function.
CVE-2020-22038MEDIUM6.5A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_v4l2_m2m_create_context function i...
CVE-2020-22037MEDIUM6.5A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.
CVE-2020-22036HIGH8.8A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_intra at libavfilter/vf_bwdif.c, which might l...
CVE-2020-22035HIGH8.8A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row at libavfilter/vf_bm3d.c, which might l...
CVE-2020-27377MEDIUM4.8A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS...
CVE-2020-26693MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attac...
CVE-2020-26670HIGH8.8A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute ...
CVE-2020-26669MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authe...
CVE-2020-26668HIGH8.8A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an...
CVE-2020-17541HIGH8.8Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a ...
CVE-2020-4561CRITICAL10IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This a...
CVE-2020-4520HIGH8.8IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the a...
CVE-2020-4354MEDIUM5.4IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit...
CVE-2020-4300HIGH8.2IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da...
CVE-2020-27748MEDIUM6.5A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allo...
CVE-2020-1920HIGH7.5A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application t...
CVE-2020-10666CRITICAL9.8The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote ...
CVE-2020-36375MEDIUM5.5Stack overflow vulnerability in parse_equality Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service ...
CVE-2020-36374MEDIUM5.5Stack overflow vulnerability in parse_comparison Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Servic...
CVE-2020-36373MEDIUM5.5Stack overflow vulnerability in parse_shifts Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (D...
CVE-2020-36372MEDIUM5.5Stack overflow vulnerability in parse_plus_minus Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Servic...
CVE-2020-36371MEDIUM5.5Stack overflow vulnerability in parse_mul_div_rem Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Servi...
CVE-2020-36370MEDIUM5.5Stack overflow vulnerability in parse_unary Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (Do...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now