2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35496MEDIUM5.5There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to sub...
CVE-2020-35495MEDIUM5.5There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the obj...
CVE-2020-35494MEDIUM6.1There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed ...
CVE-2020-35493MEDIUM5.5A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump cou...
CVE-2020-22550HIGH7.5Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to do...
CVE-2020-4942HIGH8.8IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an at...
CVE-2020-4928MEDIUM6.7IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request ...
CVE-2020-4919LOW3.8IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to imperson...
CVE-2020-4918MEDIUM4.4IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct...
CVE-2020-4917HIGH8.8IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious ...
CVE-2020-4916MEDIUM4.8IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS...
CVE-2020-4913MEDIUM4.4IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Forc...
CVE-2020-4912HIGH7.2IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when ...
CVE-2020-4910MEDIUM4.8IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS...
CVE-2020-4909MEDIUM4.8IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS...
CVE-2020-7771CRITICAL9.8The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function.
CVE-2020-28464CRITICAL9.8This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code...
CVE-2020-35965HIGH7.5decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to...
CVE-2020-35964MEDIUM6.5track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing.
CVE-2020-35963HIGH7.8flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correc...
CVE-2020-35962HIGH7.5The sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC), an Ethereum ...
CVE-2020-28841MEDIUM5.5MyDrivers64.sys in DriverGenius 9.61.3708.3054 allows attackers to cause a system crash via the ioctl command 0x9c402000...
CVE-2020-35952MEDIUM6.5login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish betwee...
CVE-2020-28852HIGH7.5In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processi...
CVE-2020-28851HIGH7.5In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- exten...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now