2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-13760HIGH8.8In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
CVE-2020-7663HIGH7.5websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension par...
CVE-2020-7662HIGH7.5websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension pars...
CVE-2020-13759HIGH7.5rust-vmm vm-memory before 0.1.1 and 0.2.x before 0.2.1 allows attackers to cause a denial of service (loss of IP network...
CVE-2020-5410HIGH7.5Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow ...
CVE-2020-3680HIGH7A race condition can occur when using the fastrpc memory mapping API. in Snapdragon Auto, Snapdragon Compute, Snapdragon...
CVE-2020-3645HIGH7.5Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes...
CVE-2020-3630HIGH7.8Possibility of out of bound access while processing the responses from video firmware in Snapdragon Auto, Snapdragon Com...
CVE-2020-3625HIGH7.8When making query to DSP capabilities, Stack out of bounds occurs due to wrong buffer length configured for DSP attribut...
CVE-2020-3623HIGH7.8kernel failure due to load failures while running v1 path directly via kernel in Snapdragon Mobile in SM8250, SXR2130
CVE-2020-3618HIGH7.8NULL exception due to accessing bad pointer while posting events on RT FIFO in Snapdragon Compute, Snapdragon Mobile, Sn...
CVE-2020-3616HIGH7.8Buffer overflow in display function due to memory copy without checking length of size using strcpy function in Snapdrag...
CVE-2020-3610HIGH7.8Possibility of double free of the drawobj that is added to the drawqueue array of the context during IOCTL commands as t...
CVE-2020-4367HIGH7.5IBM Planning Analytics Local 2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decr...
CVE-2020-13229HIGH8.8An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi...
CVE-2020-10739HIGH7.5Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contain the following vulnerability when telemetry v2 is enabled: ...
CVE-2020-9291HIGH7.8An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain eleva...
CVE-2020-13757HIGH7.5Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security...
CVE-2020-13695HIGH7.2In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges t...
CVE-2020-13694HIGH8.8In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysq...
CVE-2020-13448HIGH8.8QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execut...
CVE-2020-12062HIGH7.5The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, whi...
CVE-2020-7660HIGH8.1serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" ...
CVE-2020-7659HIGH7.5reel through 0.6.1 allows Request Smuggling attacks due to incorrect Content-Length and Transfer encoding header parsing...
CVE-2020-4020HIGH7.2The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who cont...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now