2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-14382HIGH7.8A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, tha...
CVE-2020-10733HIGH7.3The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths...
CVE-2020-7733HIGH7.5The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for ...
CVE-2020-2276HIGH8.8Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing att...
CVE-2020-2268HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain acc...
CVE-2020-2261HIGH8.8Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Confi...
CVE-2020-14393HIGH7.1A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 3...
CVE-2020-25559HIGH7.8gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary c...
CVE-2020-14386HIGH7.8A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unp...
CVE-2020-25453HIGH8.8An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote...
CVE-2020-11977HIGH7.2In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow ...
CVE-2020-15172HIGH8.8The Act module for Red Discord Bot before commit 6b9f3b86 is vulnerable to Remote Code Execution. With this exploit, Dis...
CVE-2020-14362HIGH7.8A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may...
CVE-2020-14361HIGH7.8A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may...
CVE-2020-14346HIGH7.8A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in th...
CVE-2020-8342HIGH7A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalati...
CVE-2020-4703HIGH8IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload a...
CVE-2020-4521HIGH8.8IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the...
CVE-2020-23451HIGH8.8Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" func...
CVE-2020-16101HIGH7.5It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out...
CVE-2020-16100HIGH7.5It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websoc...
CVE-2020-16096HIGH7.7In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(...
CVE-2020-14345HIGH7.8A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead...
CVE-2020-24925HIGH7.5A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3. An attacker is able to view the pa...
CVE-2020-15590HIGH7.5A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to by...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now