2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28025 | HIGH | 7.5 | 2.7% | May 6, 2021 | Exim 4 before 4.94.2 allows Out-of-bounds Read because pdkim_finish_bodyhash does not validate the relationship between ... |
| CVE-2020-28024 | CRITICAL | 9.8 | 4.1% | May 6, 2021 | Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary co... |
| CVE-2020-28023 | HIGH | 7.5 | 2.6% | May 6, 2021 | Exim 4 before 4.94.2 allows Out-of-bounds Read. smtp_setup_msg may disclose sensitive information from process memory to... |
| CVE-2020-28022 | CRITICAL | 9.8 | 3.0% | May 6, 2021 | Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer. This occurs when... |
| CVE-2020-28021 | HIGH | 8.8 | 4.1% | May 6, 2021 | Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. An authenticated remote SMTP client can insert newl... |
| CVE-2020-28020 | CRITICAL | 9.8 | 7.8% | May 6, 2021 | Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute a... |
| CVE-2020-28019 | HIGH | 7.5 | 61.1% | May 6, 2021 | Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequence... |
| CVE-2020-28018 | CRITICAL | 9.8 | 55.8% | May 6, 2021 | Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSS... |
| CVE-2020-28017 | CRITICAL | 9.8 | 36.1% | May 6, 2021 | Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fift... |
| CVE-2020-28016 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 allows an off-by-two Out-of-bounds Write because "-F ''" is mishandled by parse_fix_phrase. |
| CVE-2020-28015 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. Local users can alter the behavior of root processe... |
| CVE-2020-28014 | MEDIUM | 6.1 | 0.9% | May 6, 2021 | Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and all... |
| CVE-2020-28013 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may... |
| CVE-2020-28012 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 allows Exposure of File Descriptor to Unintended Control Sphere because rda_interpret uses a privil... |
| CVE-2020-28011 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 allows Heap-based Buffer Overflow in queue_run via two sender options: -R and -S. This may cause pr... |
| CVE-2020-28010 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 allows Out-of-bounds Write because the main function, while setuid root, copies the current working... |
| CVE-2020-28009 | HIGH | 7.8 | 0.5% | May 6, 2021 | Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow because get_stdinput allows unbounded reads that are acc... |
| CVE-2020-28008 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory ... |
| CVE-2020-28007 | HIGH | 7.8 | 0.5% | May 6, 2021 | Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (o... |
| CVE-2020-23128 | MEDIUM | 4.9 | 0.9% | May 6, 2021 | Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege t... |
| CVE-2020-23127 | HIGH | 8.8 | 0.8% | May 6, 2021 | Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin us... |
| CVE-2020-19114 | CRITICAL | 9.8 | 1.9% | May 6, 2021 | SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a re... |
| CVE-2020-19113 | CRITICAL | 9.8 | 3.0% | May 6, 2021 | Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution. |
| CVE-2020-19112 | CRITICAL | 9.8 | 1.9% | May 6, 2021 | SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a ... |
| CVE-2020-19111 | CRITICAL | 9.8 | 1.9% | May 6, 2021 | Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicio... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now