2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-27618MEDIUM5.5The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input ...
CVE-2020-27223MEDIUM5.3In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request contai...
CVE-2020-24686HIGH7.5The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leadin...
CVE-2020-28646HIGH7.8ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain dir...
CVE-2020-28199CRITICAL9.1best it Amazon Pay Plugin before 9.4.2 for Shopware exposes Sensitive Information to an Unauthorized Actor.
CVE-2020-26200MEDIUM6.8A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their...
CVE-2020-24455MEDIUM6.7Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation ...
CVE-2020-17162HIGH8.8Microsoft Windows Security Feature Bypass Vulnerability
CVE-2020-27543HIGH7.5The restify-paginate package 0.0.5 for Node.js allows remote attackers to cause a Denial-of-Service by omitting the HTTP...
CVE-2020-23534CRITICAL9.8A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.
CVE-2020-8032HIGH7A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to esc...
CVE-2020-36254HIGH8.1scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.
CVE-2020-9053Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2020-9052Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2020-9051Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2020-4931MEDIUM6.5IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to ...
CVE-2020-11988HIGH8.2Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input valida...
CVE-2020-11987HIGH8.2Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPan...
CVE-2020-7836HIGH7.8VOICEYE WSActiveBridgeES versions prior to 2.1.0.3 contains a stack-based buffer overflow vulnerability caused by improp...
CVE-2020-27224CRITICAL9.6In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute ...
CVE-2020-7846HIGH8.8Helpcom before v10.0 contains a file download and execution vulnerability caused by storing hardcoded cryptographic key....
CVE-2020-28599HIGH7.8A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-...
CVE-2020-12702MEDIUM4.6Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS...
CVE-2020-8297MEDIUM4.3Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users wit...
CVE-2020-7120MEDIUM5.3A local authenticated buffer overflow vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now