2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-13253MEDIUM5.5sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_wr...
CVE-2020-4378MEDIUM4.9IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a privileged authenticated user to perform unauthorized actions u...
CVE-2020-4358MEDIUM5.4IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to emb...
CVE-2020-4357MEDIUM4.3IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a remote attacker to obtain sensitive information when a detailed...
CVE-2020-4348MEDIUM6.5IBM Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.4 could allow an authenticated GUI user to perform...
CVE-2020-10737MEDIUM6.3A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wh...
CVE-2020-13616MEDIUM5.9The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification.
CVE-2020-13615MEDIUM5.9lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.
CVE-2020-13614MEDIUM5.9An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
CVE-2020-12392MEDIUM5.5The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can b...
CVE-2020-8170MEDIUM6.1We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie...
CVE-2020-10719MEDIUM6.5A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with larg...
CVE-2020-10751MEDIUM6.1A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed t...
CVE-2020-13487MEDIUM4.8The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript exe...
CVE-2020-3812MEDIUM5.5qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for...
CVE-2020-13486MEDIUM6.1The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.
CVE-2020-13459MEDIUM5.4An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize a...
CVE-2020-13440MEDIUM6.5ffjpeg through 2020-02-24 has an invalid write in bmp_load in bmp.c.
CVE-2020-13439MEDIUM6.5ffjpeg through 2020-02-24 has a heap-based buffer over-read in jfif_decode in jfif.c.
CVE-2020-13438MEDIUM6.5ffjpeg through 2020-02-24 has an invalid read in jfif_encode in jfif.c.
CVE-2020-13435MEDIUM5.5SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.
CVE-2020-13434MEDIUM5.5SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
CVE-2020-13430MEDIUM6.1Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
CVE-2020-13429MEDIUM5.4legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (...
CVE-2020-13424MEDIUM6.5The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now