2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-29562MEDIUM4.8The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irrev...
CVE-2020-28916MEDIUM5.5hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
CVE-2020-29561MEDIUM5.5An issue was discovered in SonicBOOM riscv-boom 3.0.0. For LR, it does not avoid acquiring a reservation in the case whe...
CVE-2020-27348MEDIUM6.8In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a mali...
CVE-2020-16123MEDIUM4.7An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a cl...
CVE-2020-26248HIGH8.2In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve d...
CVE-2020-29534HIGH7.8An issue was discovered in the Linux kernel before 5.9.3. io_uring takes a non-refcounted reference to the files_struct ...
CVE-2020-29529HIGH7.5HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protec...
CVE-2020-23741MEDIUM5.5In AnyView (network police) network monitoring software 4.6.0.1, there is a local denial of service vulnerability in Any...
CVE-2020-23740HIGH7.8In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use...
CVE-2020-23738MEDIUM5.5There is a local denial of service vulnerability in Advanced SystemCare 13 PRO 13.5.0.174. Attackers can use a construct...
CVE-2020-23736MEDIUM5.5There is a local denial of service vulnerability in DaDa accelerator 5.6.19.816,, attackers can use constructed programs...
CVE-2020-17527HIGH7.5While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 ...
CVE-2020-28175HIGH7.8There is a local privilege escalation vulnerability in Alfredo Milani Comparetti SpeedFan 4.52. Attackers can use constr...
CVE-2020-23727MEDIUM5.5There is a local denial of service vulnerability in the Antiy Zhijia Terminal Defense System 5.0.2.10121559 and an attac...
CVE-2020-23726MEDIUM5.5There is a local denial of service vulnerability in Wise Care 365 5.5.4, attackers can cause computer crash (BSOD).
CVE-2020-13525HIGH8.8The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL i...
CVE-2020-13524MEDIUM5.5An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD f...
CVE-2020-28923LOW2.7An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead...
CVE-2020-28251HIGH8.1NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be...
CVE-2020-27783MEDIUM6.1A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, ...
CVE-2020-27778HIGH7.5A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this ...
CVE-2020-27764LOW3.3In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ss...
CVE-2020-27763LOW3.3A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by Imag...
CVE-2020-27762MEDIUM5.5A flaw was found in ImageMagick in coders/hdr.c. An attacker who submits a crafted file that is processed by ImageMagick...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now