2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13253 | MEDIUM | 5.5 | 0.4% | May 27, 2020 | sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_wr... |
| CVE-2020-4378 | MEDIUM | 4.9 | 0.9% | May 27, 2020 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a privileged authenticated user to perform unauthorized actions u... |
| CVE-2020-4358 | MEDIUM | 5.4 | 0.6% | May 27, 2020 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to emb... |
| CVE-2020-4357 | MEDIUM | 4.3 | 1.0% | May 27, 2020 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a remote attacker to obtain sensitive information when a detailed... |
| CVE-2020-4348 | MEDIUM | 6.5 | 0.8% | May 27, 2020 | IBM Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.4 could allow an authenticated GUI user to perform... |
| CVE-2020-10737 | MEDIUM | 6.3 | 0.3% | May 27, 2020 | A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wh... |
| CVE-2020-13616 | MEDIUM | 5.9 | 0.9% | May 26, 2020 | The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification. |
| CVE-2020-13615 | MEDIUM | 5.9 | 0.6% | May 26, 2020 | lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates. |
| CVE-2020-13614 | MEDIUM | 5.9 | 1.9% | May 26, 2020 | An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification. |
| CVE-2020-12392 | MEDIUM | 5.5 | 0.3% | May 26, 2020 | The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can b... |
| CVE-2020-8170 | MEDIUM | 6.1 | 1.0% | May 26, 2020 | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie... |
| CVE-2020-10719 | MEDIUM | 6.5 | 1.0% | May 26, 2020 | A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with larg... |
| CVE-2020-10751 | MEDIUM | 6.1 | 0.3% | May 26, 2020 | A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed t... |
| CVE-2020-13487 | MEDIUM | 4.8 | 1.4% | May 26, 2020 | The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript exe... |
| CVE-2020-3812 | MEDIUM | 5.5 | 0.4% | May 26, 2020 | qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for... |
| CVE-2020-13486 | MEDIUM | 6.1 | 0.7% | May 25, 2020 | The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection. |
| CVE-2020-13459 | MEDIUM | 5.4 | 0.5% | May 25, 2020 | An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize a... |
| CVE-2020-13440 | MEDIUM | 6.5 | 0.8% | May 24, 2020 | ffjpeg through 2020-02-24 has an invalid write in bmp_load in bmp.c. |
| CVE-2020-13439 | MEDIUM | 6.5 | 0.8% | May 24, 2020 | ffjpeg through 2020-02-24 has a heap-based buffer over-read in jfif_decode in jfif.c. |
| CVE-2020-13438 | MEDIUM | 6.5 | 0.8% | May 24, 2020 | ffjpeg through 2020-02-24 has an invalid read in jfif_encode in jfif.c. |
| CVE-2020-13435 | MEDIUM | 5.5 | 0.6% | May 24, 2020 | SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c. |
| CVE-2020-13434 | MEDIUM | 5.5 | 1.0% | May 24, 2020 | SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c. |
| CVE-2020-13430 | MEDIUM | 6.1 | 1.7% | May 24, 2020 | Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource. |
| CVE-2020-13429 | MEDIUM | 5.4 | 0.7% | May 24, 2020 | legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (... |
| CVE-2020-13424 | MEDIUM | 6.5 | 1.7% | May 23, 2020 | The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now