2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25657MEDIUM5.9A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the...
CVE-2020-14341LOW2.7The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user ...
CVE-2020-14275CRITICAL9.8Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could al...
CVE-2020-14274HIGH7.5Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote...
CVE-2020-35655MEDIUM5.4In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because off...
CVE-2020-35654HIGH8.8In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain...
CVE-2020-35653HIGH7.1In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stri...
CVE-2020-24701MEDIUM6.1OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
CVE-2020-24700MEDIUM5.4OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconf...
CVE-2020-27637CRITICAL9.8The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to...
CVE-2020-26050HIGH7.8SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SY...
CVE-2020-16146HIGH7.5Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x thr...
CVE-2020-0471CRITICAL9.8In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetoot...
CVE-2020-27059HIGH7.8In onAuthenticated of AuthenticationClient.java, there is a possible tapjacking attack when requesting the user's finger...
CVE-2020-24027CRITICAL9.8In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling o...
CVE-2020-23631MEDIUM6.1Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-si...
CVE-2020-26298MEDIUM5.4Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerabil...
CVE-2020-24025MEDIUM5.3Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specify...
CVE-2020-13559HIGH7.5A denial-of-service vulnerability exists in the traffic-logging functionality of FreyrSCADA IEC-60879-5-104 Server Simul...
CVE-2020-4869MEDIUM6.5IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflow. A remote attacker...
CVE-2020-35701HIGH8.8An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote aut...
CVE-2020-27293HIGH7.8Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a type confusion issue while processing project files, which ...
CVE-2020-27291HIGH7.8Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds read while processing project f...
CVE-2020-27289HIGH7.8Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a null pointer dereference issue while processing project fil...
CVE-2020-27287HIGH7.8Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds write while processing project ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now