2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-36368MEDIUM5.5Stack overflow vulnerability in parse_statement Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service...
CVE-2020-36367MEDIUM5.5Stack overflow vulnerability in parse_block Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (Do...
CVE-2020-36366MEDIUM5.5Stack overflow vulnerability in parse_value Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (Do...
CVE-2020-18392MEDIUM5.5Stack overflow vulnerability in parse_array Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (Do...
CVE-2020-26642MEDIUM6.1A cross-site scripting (XSS) vulnerability has been discovered in the login page of SeaCMS version 11 which allows an at...
CVE-2020-1729MEDIUM4.4A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application se...
CVE-2020-35506MEDIUM6.7A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0....
CVE-2020-35505MEDIUM4.4A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0...
CVE-2020-35504MEDIUM6A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allo...
CVE-2020-27826MEDIUM4.2A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using A...
CVE-2020-25715MEDIUM6.1A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scri...
CVE-2020-1761MEDIUM6.1A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attac...
CVE-2020-1701MEDIUM6.5A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handl...
CVE-2020-14327MEDIUM5.5A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Function...
CVE-2020-14301MEDIUM6.5An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access netwo...
CVE-2020-22033MEDIUM6.5A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_vmafmotion.c in convolution_y_8bit, which...
CVE-2020-10774MEDIUM5.5A memory disclosure flaw was found in the Linux kernel's versions before 4.18.0-193.el8 in the sysctl subsystem when rea...
CVE-2020-10729MEDIUM5.5A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length g...
CVE-2020-10716MEDIUM6.5A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the ...
CVE-2020-10701MEDIUM6.5A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This...
CVE-2020-10697MEDIUM4.4A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker...
CVE-2020-10688MEDIUM6.1A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it...
CVE-2020-18230MEDIUM4.8Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into...
CVE-2020-18229MEDIUM4.8Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into...
CVE-2020-27831MEDIUM4.3A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addr...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now