2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-35519HIGH7.8An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc...
CVE-2020-28025HIGH7.5Exim 4 before 4.94.2 allows Out-of-bounds Read because pdkim_finish_bodyhash does not validate the relationship between ...
CVE-2020-28023HIGH7.5Exim 4 before 4.94.2 allows Out-of-bounds Read. smtp_setup_msg may disclose sensitive information from process memory to...
CVE-2020-28021HIGH8.8Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. An authenticated remote SMTP client can insert newl...
CVE-2020-28019HIGH7.5Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequence...
CVE-2020-28016HIGH7.8Exim 4 before 4.94.2 allows an off-by-two Out-of-bounds Write because "-F ''" is mishandled by parse_fix_phrase.
CVE-2020-28015HIGH7.8Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. Local users can alter the behavior of root processe...
CVE-2020-28013HIGH7.8Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may...
CVE-2020-28012HIGH7.8Exim 4 before 4.94.2 allows Exposure of File Descriptor to Unintended Control Sphere because rda_interpret uses a privil...
CVE-2020-28011HIGH7.8Exim 4 before 4.94.2 allows Heap-based Buffer Overflow in queue_run via two sender options: -R and -S. This may cause pr...
CVE-2020-28010HIGH7.8Exim 4 before 4.94.2 allows Out-of-bounds Write because the main function, while setuid root, copies the current working...
CVE-2020-28009HIGH7.8Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow because get_stdinput allows unbounded reads that are acc...
CVE-2020-28008HIGH7.8Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory ...
CVE-2020-28007HIGH7.8Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (o...
CVE-2020-23127HIGH8.8Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin us...
CVE-2020-5013HIGH8.1IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A r...
CVE-2020-4932HIGH7.8IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for ...
CVE-2020-13664HIGH8.8Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an admini...
CVE-2020-36334HIGH8.8themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.
CVE-2020-21999HIGH8.8iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using de...
CVE-2020-27518HIGH7.8All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the...
CVE-2020-35756HIGH7.5An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Passwor...
CVE-2020-35755HIGH7.5An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Inf...
CVE-2020-28944HIGH7.5OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of d...
CVE-2020-7731HIGH7.5This affects all versions <0.7.0 of package github.com/russellhaering/gosaml2. There is a crash on nil-pointer dereferen...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now