2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-29375HIGH8.8An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 a...
CVE-2020-29374LOW3.6An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (...
CVE-2020-29373MEDIUM6.5An issue was discovered in fs/io_uring.c in the Linux kernel before 5.6. It unsafely handles the root directory during p...
CVE-2020-29372MEDIUM4.7An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition betwee...
CVE-2020-29371LOW3.3An issue was discovered in romfs_dev_read in fs/romfs/storage.c in the Linux kernel before 5.8.4. Uninitialized memory l...
CVE-2020-29370HIGH7An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the ...
CVE-2020-29369HIGH7An issue was discovered in mm/mmap.c in the Linux kernel before 5.7.11. There is a race condition between certain expand...
CVE-2020-29368HIGH7An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write impl...
CVE-2020-27218MEDIUM4.8In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2...
CVE-2020-29367HIGH7.8blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write ...
CVE-2020-26245CRITICAL9.8npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. T...
CVE-2020-28922HIGH8.8An issue was discovered in Devid Espenschied PC Analyser through 4.10. The PCADRVX64.SYS kernel driver exposes IOCTL fun...
CVE-2020-28921HIGH8.8An issue was discovered in Devid Espenschied PC Analyser through 4.10. The PCADRVX64.SYS kernel driver exposes IOCTL fun...
CVE-2020-27746LOW3.7Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X1...
CVE-2020-25708HIGH7.5A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a speci...
CVE-2020-25014CRITICAL9.8A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4...
CVE-2020-10772HIGH7.5An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020...
CVE-2020-7780HIGH8.8This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-h...
CVE-2020-27745CRITICAL9.8Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.
CVE-2020-29138MEDIUM5.3Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, all...
CVE-2020-25738MEDIUM5.5CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism ...
CVE-2020-29145MEDIUM5.4In Ericsson BSCS iX R18 Billing & Rating iX R18, ADMX is a web base module in BSCS iX that is vulnerable to stored XSS v...
CVE-2020-29144MEDIUM5.4In Ericsson BSCS iX R18 Billing & Rating iX R18, MX is a web base module in BSCS iX that is vulnerable to stored XSS via...
CVE-2020-29137MEDIUM6.1cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).
CVE-2020-29136MEDIUM6.5In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now