2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-27802MEDIUM5.5An floating point exception was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O ...
CVE-2020-27798MEDIUM5.5An invalid memory address reference was discovered in the adjABS function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mac...
CVE-2020-27797MEDIUM5.5An invalid memory address reference was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted...
CVE-2020-35509MEDIUM5.4A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direc...
CVE-2020-35992MEDIUM6.5Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access t...
CVE-2020-23466MEDIUM5.4Cross Site Scripting (XSS) vulnerability exists in the phpgurukul Online Marriage Registration System 1.0 allows attacke...
CVE-2020-27788MEDIUM5.5An out-of-bounds read access vulnerability was discovered in UPX in PackLinuxElf64::canPack() function of p_lx_elf.cpp f...
CVE-2020-27790MEDIUM5.5A floating point exception issue was discovered in UPX in PackLinuxElf64::invert_pt_dynamic() function of p_lx_elf.cpp f...
CVE-2020-27787MEDIUM5.5A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input...
CVE-2020-1755MEDIUM5.3In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to...
CVE-2020-14379MEDIUM5.6A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading ...
CVE-2020-14320MEDIUM6.1In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflect...
CVE-2020-10710MEDIUM4.4A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satell...
CVE-2020-1754MEDIUM4.3In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' ...
CVE-2020-1691MEDIUM5.4In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stor...
CVE-2020-36290MEDIUM5.4The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and fro...
CVE-2020-7649MEDIUM4.9This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's inter...
CVE-2020-28459MEDIUM6.1This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx fo...
CVE-2020-28455MEDIUM6.1This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are ...
CVE-2020-36558MEDIUM5.1A race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lead to a NULL pointer dereference and gene...
CVE-2020-36557MEDIUM5.1A race condition in the Linux kernel before 5.6.2 between the VT_DISALLOCATE ioctl and closing/opening of ttys could lea...
CVE-2020-23563MEDIUM5.5IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000002cba.
CVE-2020-23562MEDIUM5.5IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000aefe.
CVE-2020-23561MEDIUM5.5IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000005722.
CVE-2020-35305MEDIUM6.1Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now