2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-27761LOW3.3WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could lead to values outsid...
CVE-2020-27760MEDIUM5.5In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero co...
CVE-2020-27759LOW3.3In IntensityCompare() of /MagickCore/quantize.c, a double value was being casted to int and returned, which in some case...
CVE-2020-25711MEDIUM6.5A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server...
CVE-2020-25693HIGH8.1A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() ca...
CVE-2020-25649HIGH7.5A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allow...
CVE-2020-23735HIGH7.8In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability. Attackers can use the constru...
CVE-2020-14381HIGH7.8A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory ...
CVE-2020-14351HIGH7.8A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local atta...
CVE-2020-14339HIGH8.8A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This fil...
CVE-2020-13584HIGH8.8An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web...
CVE-2020-13543HIGH8.8A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web...
CVE-2020-13542HIGH7.8A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depend...
CVE-2020-13531HIGH8.8A use-after-free vulnerability exists in a way Pixar OpenUSD 20.08 processes reference paths textual USD files. A specia...
CVE-2020-2324HIGH7.5Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2323MEDIUM5.3Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers w...
CVE-2020-2322HIGH7.5Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attac...
CVE-2020-2321HIGH8.1A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to s...
CVE-2020-2320CRITICAL9.8Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.
CVE-2020-28939HIGH7.2OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability al...
CVE-2020-28938MEDIUM5.4OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application...
CVE-2020-28937HIGH7.5OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to acce...
CVE-2020-14318MEDIUM4.3A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to g...
CVE-2020-6021HIGH7.8Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which t...
CVE-2020-6017CRITICAL9.8Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_Rece...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now