2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28025HIGH7.5Exim 4 before 4.94.2 allows Out-of-bounds Read because pdkim_finish_bodyhash does not validate the relationship between ...
CVE-2020-28024CRITICAL9.8Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary co...
CVE-2020-28023HIGH7.5Exim 4 before 4.94.2 allows Out-of-bounds Read. smtp_setup_msg may disclose sensitive information from process memory to...
CVE-2020-28022CRITICAL9.8Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer. This occurs when...
CVE-2020-28021HIGH8.8Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. An authenticated remote SMTP client can insert newl...
CVE-2020-28020CRITICAL9.8Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute a...
CVE-2020-28019HIGH7.5Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequence...
CVE-2020-28018CRITICAL9.8Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSS...
CVE-2020-28017CRITICAL9.8Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fift...
CVE-2020-28016HIGH7.8Exim 4 before 4.94.2 allows an off-by-two Out-of-bounds Write because "-F ''" is mishandled by parse_fix_phrase.
CVE-2020-28015HIGH7.8Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. Local users can alter the behavior of root processe...
CVE-2020-28014MEDIUM6.1Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and all...
CVE-2020-28013HIGH7.8Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may...
CVE-2020-28012HIGH7.8Exim 4 before 4.94.2 allows Exposure of File Descriptor to Unintended Control Sphere because rda_interpret uses a privil...
CVE-2020-28011HIGH7.8Exim 4 before 4.94.2 allows Heap-based Buffer Overflow in queue_run via two sender options: -R and -S. This may cause pr...
CVE-2020-28010HIGH7.8Exim 4 before 4.94.2 allows Out-of-bounds Write because the main function, while setuid root, copies the current working...
CVE-2020-28009HIGH7.8Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow because get_stdinput allows unbounded reads that are acc...
CVE-2020-28008HIGH7.8Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory ...
CVE-2020-28007HIGH7.8Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (o...
CVE-2020-23128MEDIUM4.9Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege t...
CVE-2020-23127HIGH8.8Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin us...
CVE-2020-19114CRITICAL9.8SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a re...
CVE-2020-19113CRITICAL9.8Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.
CVE-2020-19112CRITICAL9.8SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a ...
CVE-2020-19111CRITICAL9.8Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicio...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now