2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9889HIGH7.8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13....
CVE-2020-9888HIGH7.8An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macO...
CVE-2020-9885MEDIUM5.5An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verification. This issue i...
CVE-2020-9884HIGH7.8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13....
CVE-2020-9878HIGH7.8A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, ma...
CVE-2020-9870HIGH8.8A logic issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10...
CVE-2020-9865HIGH8.6A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6...
CVE-2020-9864CRITICAL9.8A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.6. An application ma...
CVE-2020-9862HIGH7.8A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed...
CVE-2020-9799HIGH7.8An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.6. A mali...
CVE-2020-4636HIGH7.2IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Fo...
CVE-2020-4254HIGH7.5IBM Security Guardium Big Data Intelligence 1.0 (SonarG) uses weaker than expected cryptographic algorithms that could a...
CVE-2020-15258HIGH8In Wire before 3.20.x, `shell.openExternal` was used without checking the URL. This vulnerability allows an attacker to ...
CVE-2020-15255HIGH7.3In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could...
CVE-2020-15254CRITICAL9.8Crossbeam is a set of tools for concurrent programming. In crossbeam-channel before version 0.4.4, the bounded channel i...
CVE-2020-15252HIGH8.8In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to th...
CVE-2020-15157MEDIUM6.1In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability...
CVE-2020-27178HIGH7.5Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret key...
CVE-2020-26672MEDIUM5.4Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user in...
CVE-2020-24408MEDIUM6.1Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upl...
CVE-2020-3991HIGH7.1VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-service vulnerability due to a file system acc...
CVE-2020-26944CRITICAL9.8An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the name...
CVE-2020-26682HIGH8.8In libass 0.14.0, the `ass_outline_construct`'s call to `outline_stroke` causes a signed integer overflow.
CVE-2020-16270MEDIUM6.1OLIMPOKS under 3.3.39 allows Auth/Admin ErrorMessage XSS. Remote Attacker can use discovered vulnerability to inject mal...
CVE-2020-15867HIGH7.2The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privile...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now