2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13760 | HIGH | 8.8 | 0.7% | Jun 2, 2020 | In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF. |
| CVE-2020-7663 | HIGH | 7.5 | 4.3% | Jun 2, 2020 | websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension par... |
| CVE-2020-7662 | HIGH | 7.5 | 3.0% | Jun 2, 2020 | websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension pars... |
| CVE-2020-13759 | HIGH | 7.5 | 1.6% | Jun 2, 2020 | rust-vmm vm-memory before 0.1.1 and 0.2.x before 0.2.1 allows attackers to cause a denial of service (loss of IP network... |
| CVE-2020-5410 | HIGH | 7.5 | 95.6% | Jun 2, 2020 | Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow ... |
| CVE-2020-3680 | HIGH | 7 | 0.2% | Jun 2, 2020 | A race condition can occur when using the fastrpc memory mapping API. in Snapdragon Auto, Snapdragon Compute, Snapdragon... |
| CVE-2020-3645 | HIGH | 7.5 | 0.7% | Jun 2, 2020 | Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes... |
| CVE-2020-3630 | HIGH | 7.8 | 0.2% | Jun 2, 2020 | Possibility of out of bound access while processing the responses from video firmware in Snapdragon Auto, Snapdragon Com... |
| CVE-2020-3625 | HIGH | 7.8 | 0.2% | Jun 2, 2020 | When making query to DSP capabilities, Stack out of bounds occurs due to wrong buffer length configured for DSP attribut... |
| CVE-2020-3623 | HIGH | 7.8 | 0.2% | Jun 2, 2020 | kernel failure due to load failures while running v1 path directly via kernel in Snapdragon Mobile in SM8250, SXR2130 |
| CVE-2020-3618 | HIGH | 7.8 | 0.2% | Jun 2, 2020 | NULL exception due to accessing bad pointer while posting events on RT FIFO in Snapdragon Compute, Snapdragon Mobile, Sn... |
| CVE-2020-3616 | HIGH | 7.8 | 0.2% | Jun 2, 2020 | Buffer overflow in display function due to memory copy without checking length of size using strcpy function in Snapdrag... |
| CVE-2020-3610 | HIGH | 7.8 | 0.2% | Jun 2, 2020 | Possibility of double free of the drawobj that is added to the drawqueue array of the context during IOCTL commands as t... |
| CVE-2020-4367 | HIGH | 7.5 | 0.8% | Jun 2, 2020 | IBM Planning Analytics Local 2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decr... |
| CVE-2020-13229 | HIGH | 8.8 | 1.6% | Jun 2, 2020 | An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi... |
| CVE-2020-10739 | HIGH | 7.5 | 2.3% | Jun 2, 2020 | Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contain the following vulnerability when telemetry v2 is enabled: ... |
| CVE-2020-9291 | HIGH | 7.8 | 0.5% | Jun 1, 2020 | An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain eleva... |
| CVE-2020-13757 | HIGH | 7.5 | 1.4% | Jun 1, 2020 | Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security... |
| CVE-2020-13695 | HIGH | 7.2 | 1.4% | Jun 1, 2020 | In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges t... |
| CVE-2020-13694 | HIGH | 8.8 | 1.7% | Jun 1, 2020 | In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysq... |
| CVE-2020-13448 | HIGH | 8.8 | 17.8% | Jun 1, 2020 | QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execut... |
| CVE-2020-12062 | HIGH | 7.5 | 2.3% | Jun 1, 2020 | The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, whi... |
| CVE-2020-7660 | HIGH | 8.1 | 3.0% | Jun 1, 2020 | serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" ... |
| CVE-2020-7659 | HIGH | 7.5 | 1.3% | Jun 1, 2020 | reel through 0.6.1 allows Request Smuggling attacks due to incorrect Content-Length and Transfer encoding header parsing... |
| CVE-2020-4020 | HIGH | 7.2 | 1.7% | Jun 1, 2020 | The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who cont... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now