2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27761 | LOW | 3.3 | 1.1% | Dec 3, 2020 | WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could lead to values outsid... |
| CVE-2020-27760 | MEDIUM | 5.5 | 1.4% | Dec 3, 2020 | In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero co... |
| CVE-2020-27759 | LOW | 3.3 | 1.1% | Dec 3, 2020 | In IntensityCompare() of /MagickCore/quantize.c, a double value was being casted to int and returned, which in some case... |
| CVE-2020-25711 | MEDIUM | 6.5 | 1.1% | Dec 3, 2020 | A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server... |
| CVE-2020-25693 | HIGH | 8.1 | 1.5% | Dec 3, 2020 | A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() ca... |
| CVE-2020-25649 | HIGH | 7.5 | 17.6% | Dec 3, 2020 | A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allow... |
| CVE-2020-23735 | HIGH | 7.8 | 0.3% | Dec 3, 2020 | In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability. Attackers can use the constru... |
| CVE-2020-14381 | HIGH | 7.8 | 0.8% | Dec 3, 2020 | A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory ... |
| CVE-2020-14351 | HIGH | 7.8 | 0.3% | Dec 3, 2020 | A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local atta... |
| CVE-2020-14339 | HIGH | 8.8 | 0.4% | Dec 3, 2020 | A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This fil... |
| CVE-2020-13584 | HIGH | 8.8 | 4.4% | Dec 3, 2020 | An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web... |
| CVE-2020-13543 | HIGH | 8.8 | 3.3% | Dec 3, 2020 | A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web... |
| CVE-2020-13542 | HIGH | 7.8 | 0.6% | Dec 3, 2020 | A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depend... |
| CVE-2020-13531 | HIGH | 8.8 | 2.7% | Dec 3, 2020 | A use-after-free vulnerability exists in a way Pixar OpenUSD 20.08 processes reference paths textual USD files. A specia... |
| CVE-2020-2324 | HIGH | 7.5 | 1.3% | Dec 3, 2020 | Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2020-2323 | MEDIUM | 5.3 | 0.8% | Dec 3, 2020 | Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers w... |
| CVE-2020-2322 | HIGH | 7.5 | 1.3% | Dec 3, 2020 | Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attac... |
| CVE-2020-2321 | HIGH | 8.1 | 0.7% | Dec 3, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to s... |
| CVE-2020-2320 | CRITICAL | 9.8 | 0.9% | Dec 3, 2020 | Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads. |
| CVE-2020-28939 | HIGH | 7.2 | 1.7% | Dec 3, 2020 | OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability al... |
| CVE-2020-28938 | MEDIUM | 5.4 | 0.5% | Dec 3, 2020 | OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application... |
| CVE-2020-28937 | HIGH | 7.5 | 1.3% | Dec 3, 2020 | OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to acce... |
| CVE-2020-14318 | MEDIUM | 4.3 | 1.5% | Dec 3, 2020 | A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to g... |
| CVE-2020-6021 | HIGH | 7.8 | 0.3% | Dec 3, 2020 | Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which t... |
| CVE-2020-6017 | CRITICAL | 9.8 | 3.1% | Dec 3, 2020 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_Rece... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now