2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2020-23250LOW2.3GigaVUE-OS (GVOS) 5.4 - 5.9 uses a weak algorithm for a hash stored in internal database.
CVE-2020-4919LOW3.8IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to imperson...
CVE-2020-11947LOW3.8iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated informat...
CVE-2020-35448LOW3.3An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1....
CVE-2020-2505LOW2.3If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. Q...
CVE-2020-24693LOW3.3The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow a local attacker to view system informat...
CVE-2020-4846LOW2.7IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a de...
CVE-2020-4906LOW3.3IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally whic...
CVE-2020-4008LOW3.6The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure wa...
CVE-2020-29480LOW2.3An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting...
CVE-2020-27057LOW3.3In getGpuStatsGlobalInfo and getGpuStatsAppInfo of GpuService.cpp, there is a possible permission bypass due to a missin...
CVE-2020-27056LOW3.3In SELinux policies of mls, there is a missing permission check. This could lead to local information disclosure of pack...
CVE-2020-0481LOW3.3In AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege allowin...
CVE-2020-0368LOW3.3In queryInternal of CallLogProvider.java, there is a possible permission bypass due to improper input validation. This c...
CVE-2020-8938LOW3.3An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to From...
CVE-2020-8937LOW3.3An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to enc_...
CVE-2020-0459LOW3.3In sendConfiguredNetworkChangedBroadcast of WifiConfigManager.java, there is a possible leak of sensitive WiFi configura...
CVE-2020-8284LOW3.7A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP add...
CVE-2020-28838LOW3.5Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items...
CVE-2020-8908LOW3.3A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine...
CVE-2020-26270LOW3.3In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length...
CVE-2020-26271LOW3.3In affected versions of TensorFlow under certain cases, loading a saved model can result in accessing uninitialized memo...
CVE-2020-8920LOW3.5An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 wh...
CVE-2020-8919LOW3.5An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a mis...
CVE-2020-29668LOW3.7Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except on...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now