2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35496 | MEDIUM | 5.5 | 1.1% | Jan 4, 2021 | There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to sub... |
| CVE-2020-35495 | MEDIUM | 5.5 | 1.2% | Jan 4, 2021 | There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the obj... |
| CVE-2020-35494 | MEDIUM | 6.1 | 1.1% | Jan 4, 2021 | There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed ... |
| CVE-2020-35493 | MEDIUM | 5.5 | 1.1% | Jan 4, 2021 | A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump cou... |
| CVE-2020-22550 | HIGH | 7.5 | 2.2% | Jan 4, 2021 | Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to do... |
| CVE-2020-4942 | HIGH | 8.8 | 0.5% | Jan 4, 2021 | IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an at... |
| CVE-2020-4928 | MEDIUM | 6.7 | 0.4% | Jan 4, 2021 | IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request ... |
| CVE-2020-4919 | LOW | 3.8 | 0.6% | Jan 4, 2021 | IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to imperson... |
| CVE-2020-4918 | MEDIUM | 4.4 | 0.3% | Jan 4, 2021 | IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct... |
| CVE-2020-4917 | HIGH | 8.8 | 0.4% | Jan 4, 2021 | IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious ... |
| CVE-2020-4916 | MEDIUM | 4.8 | 0.7% | Jan 4, 2021 | IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS... |
| CVE-2020-4913 | MEDIUM | 4.4 | 0.3% | Jan 4, 2021 | IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Forc... |
| CVE-2020-4912 | HIGH | 7.2 | 1.1% | Jan 4, 2021 | IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when ... |
| CVE-2020-4910 | MEDIUM | 4.8 | 0.5% | Jan 4, 2021 | IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS... |
| CVE-2020-4909 | MEDIUM | 4.8 | 0.5% | Jan 4, 2021 | IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS... |
| CVE-2020-7771 | CRITICAL | 9.8 | 1.9% | Jan 4, 2021 | The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function. |
| CVE-2020-28464 | CRITICAL | 9.8 | 3.0% | Jan 4, 2021 | This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code... |
| CVE-2020-35965 | HIGH | 7.5 | 2.3% | Jan 4, 2021 | decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to... |
| CVE-2020-35964 | MEDIUM | 6.5 | 1.5% | Jan 3, 2021 | track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing. |
| CVE-2020-35963 | HIGH | 7.8 | 1.3% | Jan 3, 2021 | flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correc... |
| CVE-2020-35962 | HIGH | 7.5 | 1.3% | Jan 3, 2021 | The sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC), an Ethereum ... |
| CVE-2020-28841 | MEDIUM | 5.5 | 0.8% | Jan 3, 2021 | MyDrivers64.sys in DriverGenius 9.61.3708.3054 allows attackers to cause a system crash via the ioctl command 0x9c402000... |
| CVE-2020-35952 | MEDIUM | 6.5 | 0.9% | Jan 3, 2021 | login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish betwee... |
| CVE-2020-28852 | HIGH | 7.5 | 1.7% | Jan 2, 2021 | In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processi... |
| CVE-2020-28851 | HIGH | 7.5 | 2.3% | Jan 2, 2021 | In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- exten... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now