2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29562 | MEDIUM | 4.8 | 1.5% | Dec 4, 2020 | The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irrev... |
| CVE-2020-28916 | MEDIUM | 5.5 | 0.7% | Dec 4, 2020 | hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address. |
| CVE-2020-29561 | MEDIUM | 5.5 | 0.6% | Dec 4, 2020 | An issue was discovered in SonicBOOM riscv-boom 3.0.0. For LR, it does not avoid acquiring a reservation in the case whe... |
| CVE-2020-27348 | MEDIUM | 6.8 | 0.7% | Dec 4, 2020 | In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a mali... |
| CVE-2020-16123 | MEDIUM | 4.7 | 0.3% | Dec 4, 2020 | An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a cl... |
| CVE-2020-26248 | HIGH | 8.2 | 12.4% | Dec 3, 2020 | In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve d... |
| CVE-2020-29534 | HIGH | 7.8 | 0.5% | Dec 3, 2020 | An issue was discovered in the Linux kernel before 5.9.3. io_uring takes a non-refcounted reference to the files_struct ... |
| CVE-2020-29529 | HIGH | 7.5 | 2.8% | Dec 3, 2020 | HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protec... |
| CVE-2020-23741 | MEDIUM | 5.5 | 0.3% | Dec 3, 2020 | In AnyView (network police) network monitoring software 4.6.0.1, there is a local denial of service vulnerability in Any... |
| CVE-2020-23740 | HIGH | 7.8 | 0.3% | Dec 3, 2020 | In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use... |
| CVE-2020-23738 | MEDIUM | 5.5 | 0.4% | Dec 3, 2020 | There is a local denial of service vulnerability in Advanced SystemCare 13 PRO 13.5.0.174. Attackers can use a construct... |
| CVE-2020-23736 | MEDIUM | 5.5 | 0.4% | Dec 3, 2020 | There is a local denial of service vulnerability in DaDa accelerator 5.6.19.816,, attackers can use constructed programs... |
| CVE-2020-17527 | HIGH | 7.5 | 24.6% | Dec 3, 2020 | While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 ... |
| CVE-2020-28175 | HIGH | 7.8 | 0.5% | Dec 3, 2020 | There is a local privilege escalation vulnerability in Alfredo Milani Comparetti SpeedFan 4.52. Attackers can use constr... |
| CVE-2020-23727 | MEDIUM | 5.5 | 0.4% | Dec 3, 2020 | There is a local denial of service vulnerability in the Antiy Zhijia Terminal Defense System 5.0.2.10121559 and an attac... |
| CVE-2020-23726 | MEDIUM | 5.5 | 0.3% | Dec 3, 2020 | There is a local denial of service vulnerability in Wise Care 365 5.5.4, attackers can cause computer crash (BSOD). |
| CVE-2020-13525 | HIGH | 8.8 | 1.7% | Dec 3, 2020 | The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL i... |
| CVE-2020-13524 | MEDIUM | 5.5 | 0.8% | Dec 3, 2020 | An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD f... |
| CVE-2020-28923 | LOW | 2.7 | 1.0% | Dec 3, 2020 | An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead... |
| CVE-2020-28251 | HIGH | 8.1 | 1.2% | Dec 3, 2020 | NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be... |
| CVE-2020-27783 | MEDIUM | 6.1 | 3.9% | Dec 3, 2020 | A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, ... |
| CVE-2020-27778 | HIGH | 7.5 | 2.2% | Dec 3, 2020 | A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this ... |
| CVE-2020-27764 | LOW | 3.3 | 1.1% | Dec 3, 2020 | In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ss... |
| CVE-2020-27763 | LOW | 3.3 | 0.9% | Dec 3, 2020 | A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by Imag... |
| CVE-2020-27762 | MEDIUM | 5.5 | 1.1% | Dec 3, 2020 | A flaw was found in ImageMagick in coders/hdr.c. An attacker who submits a crafted file that is processed by ImageMagick... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now