2020 CVE Vulnerabilities

21,060 CVEs published in 2020.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2020-4919LOW3.8IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to imperson...
CVE-2020-11947LOW3.8iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated informat...
CVE-2020-35448LOW3.3An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1....
CVE-2020-2505LOW2.3If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. Q...
CVE-2020-24693LOW3.3The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow a local attacker to view system informat...
CVE-2020-4846LOW2.7IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a de...
CVE-2020-4906LOW3.3IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally whic...
CVE-2020-4008LOW3.6The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure wa...
CVE-2020-29480LOW2.3An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting...
CVE-2020-27057LOW3.3In getGpuStatsGlobalInfo and getGpuStatsAppInfo of GpuService.cpp, there is a possible permission bypass due to a missin...
CVE-2020-27056LOW3.3In SELinux policies of mls, there is a missing permission check. This could lead to local information disclosure of pack...
CVE-2020-0481LOW3.3In AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege allowin...
CVE-2020-0368LOW3.3In queryInternal of CallLogProvider.java, there is a possible permission bypass due to improper input validation. This c...
CVE-2020-8938LOW3.3An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to From...
CVE-2020-8937LOW3.3An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to enc_...
CVE-2020-0459LOW3.3In sendConfiguredNetworkChangedBroadcast of WifiConfigManager.java, there is a possible leak of sensitive WiFi configura...
CVE-2020-8284LOW3.7A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP add...
CVE-2020-28838LOW3.5Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items...
CVE-2020-8908LOW3.3A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine...
CVE-2020-26270LOW3.3In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length...
CVE-2020-26271LOW3.3In affected versions of TensorFlow under certain cases, loading a saved model can result in accessing uninitialized memo...
CVE-2020-8920LOW3.5An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 wh...
CVE-2020-8919LOW3.5An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a mis...
CVE-2020-29668LOW3.7Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except on...
CVE-2020-27351LOW2.8Various memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile....

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now