2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9863HIGH7.8A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13...
CVE-2020-9854HIGH7.8A logic issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10...
CVE-2020-9853HIGH7.8A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A malic...
CVE-2020-9828HIGH7.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A rem...
CVE-2020-9810MEDIUM6.8A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. A person with phy...
CVE-2020-9796HIGH7A race condition was addressed with improved state handling. This issue is fixed in macOS Catalina 10.15.5. An applicati...
CVE-2020-9787MEDIUM5.3A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina ...
CVE-2020-9779HIGH7.1An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A loc...
CVE-2020-9772MEDIUM5.5A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina ...
CVE-2020-9771HIGH7.1This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A user may gain access t...
CVE-2020-3918MEDIUM5.5An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, mac...
CVE-2020-3915HIGH7.8A path handling issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A malicious...
CVE-2020-3898HIGH7.8A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An appl...
CVE-2020-15906CRITICAL9.8tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
CVE-2020-7020LOW3.1Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security ...
CVE-2020-27195CRITICAL9.1HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using eithe...
CVE-2020-27155HIGH7.5An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted te...
CVE-2020-27533MEDIUM5.4A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to ...
CVE-2020-26650MEDIUM5.3AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
CVE-2020-26649HIGH8.1AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php
CVE-2020-27646MEDIUM6.5Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.
CVE-2020-27560LOW3.3ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of ...
CVE-2020-24033HIGH8.8An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authe...
CVE-2020-27642MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Gre...
CVE-2020-27638HIGH7.5receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type c...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now