2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27985 | HIGH | 7.8 | 0.5% | Nov 23, 2020 | Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain ro... |
| CVE-2020-28975 | HIGH | 7.5 | 3.4% | Nov 21, 2020 | svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cau... |
| CVE-2020-14258 | HIGH | 7.5 | 1.2% | Nov 21, 2020 | HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A re... |
| CVE-2020-14234 | HIGH | 7.5 | 1.0% | Nov 21, 2020 | HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potent... |
| CVE-2020-14230 | HIGH | 7.5 | 1.2% | Nov 21, 2020 | HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A r... |
| CVE-2020-25189 | CRITICAL | 9.8 | 2.5% | Nov 21, 2020 | The affected product is vulnerable to three stack-based buffer overflows, which may allow an unauthenticated attacker to... |
| CVE-2020-5797 | MEDIUM | 6.1 | 0.6% | Nov 21, 2020 | UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with... |
| CVE-2020-25725 | MEDIUM | 5.5 | 1.0% | Nov 21, 2020 | In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3Glyph... |
| CVE-2020-25185 | HIGH | 8.8 | 2.1% | Nov 21, 2020 | The affected product is vulnerable to five post-authentication buffer overflows, which may allow a logged in user to rem... |
| CVE-2020-4005 | HIGH | 7.8 | 0.4% | Nov 20, 2020 | VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a... |
| CVE-2020-4004 | HIGH | 8.2 | 0.4% | Nov 20, 2020 | VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstati... |
| CVE-2020-28845 | HIGH | 7.8 | 1.1% | Nov 20, 2020 | A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious p... |
| CVE-2020-20740 | HIGH | 7.8 | 1.0% | Nov 20, 2020 | PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version(). |
| CVE-2020-20739 | MEDIUM | 5.3 | 2.0% | Nov 20, 2020 | im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may c... |
| CVE-2020-28974 | MEDIUM | 5 | 0.5% | Nov 20, 2020 | A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged ... |
| CVE-2020-26236 | HIGH | 7.5 | 0.9% | Nov 20, 2020 | In ScratchVerifier before commit a603769, an attacker can hijack the verification process to log into someone else's acc... |
| CVE-2020-7842 | MEDIUM | 6.6 | 1.5% | Nov 20, 2020 | Improper Input validation vulnerability exists in Netis Korea D'live AP which could cause arbitrary command injection an... |
| CVE-2020-28877 | CRITICAL | 9.8 | 1.2% | Nov 20, 2020 | Buffer overflow in in the copy_msg_element function for the devDiscoverHandle server in the TP-Link WR and WDR series, i... |
| CVE-2020-25839 | CRITICAL | 9.8 | 1.2% | Nov 20, 2020 | NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability i... |
| CVE-2020-19668 | MEDIUM | 6.5 | 0.9% | Nov 20, 2020 | Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6... |
| CVE-2020-19667 | HIGH | 7.8 | 1.6% | Nov 20, 2020 | Stack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.0.10-7. |
| CVE-2020-13671 | HIGH | 8.8 | 4.3% | Nov 20, 2020 | Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as... |
| CVE-2020-4937 | HIGH | 7.5 | 0.8% | Nov 20, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms ... |
| CVE-2020-4739 | HIGH | 7.8 | 0.4% | Nov 20, 2020 | IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.... |
| CVE-2020-5668 | HIGH | 7.5 | 4.7% | Nov 20, 2020 | Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series modules (R00/01/02CPU firmware version '19' and ea... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now