2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36779MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: i2c: stm32f7: fix reference leak when pm_runtime_ge...
CVE-2020-36778MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: i2c: xiic: fix reference leak when pm_runtime_get_s...
CVE-2020-36777MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: Fix memory leak in dvb_media_device_...
CVE-2020-36776MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/cpufreq_cooling: Fix slab OOB issue...
CVE-2020-36775MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential deadlock Using f2fs_t...
CVE-2020-36774MEDIUM5.5plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for Glad...
CVE-2020-36773CRITICAL9.8Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwri...
CVE-2020-29504CRITICAL9.8 Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, co...
CVE-2020-24682HIGH7.8Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation ...
CVE-2020-24681HIGH8.8Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allow...
CVE-2020-36772MEDIUM4.4CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allo...
CVE-2020-36771HIGH7.8CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations th...
CVE-2020-36770CRITICAL9.8pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on file...
CVE-2020-26630MEDIUM4.9A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker t...
CVE-2020-26629CRITICAL9.8A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows...
CVE-2020-26628MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to...
CVE-2020-26627MEDIUM4.9A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker t...
CVE-2020-13880CRITICAL9.8IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+1cbf heap-based out-of-bounds write.
CVE-2020-13879CRITICAL9.8IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+214f heap-based out-of-bounds write.
CVE-2020-13878CRITICAL9.8IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+27ef heap-based out-of-bounds write.
CVE-2020-26625LOW3.8A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute ar...
CVE-2020-26624LOW3.8A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute ar...
CVE-2020-26623LOW3.8SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web ...
CVE-2020-17163HIGH7.8Visual Studio Code Python Extension Remote Code Execution Vulnerability
CVE-2020-36769MEDIUM5.4The Widget Settings Importer/Exporter Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp_ajax...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now