2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35519 | HIGH | 7.8 | 0.4% | May 6, 2021 | An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc... |
| CVE-2020-28025 | HIGH | 7.5 | 2.7% | May 6, 2021 | Exim 4 before 4.94.2 allows Out-of-bounds Read because pdkim_finish_bodyhash does not validate the relationship between ... |
| CVE-2020-28023 | HIGH | 7.5 | 2.6% | May 6, 2021 | Exim 4 before 4.94.2 allows Out-of-bounds Read. smtp_setup_msg may disclose sensitive information from process memory to... |
| CVE-2020-28021 | HIGH | 8.8 | 4.1% | May 6, 2021 | Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. An authenticated remote SMTP client can insert newl... |
| CVE-2020-28019 | HIGH | 7.5 | 61.1% | May 6, 2021 | Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequence... |
| CVE-2020-28016 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 allows an off-by-two Out-of-bounds Write because "-F ''" is mishandled by parse_fix_phrase. |
| CVE-2020-28015 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. Local users can alter the behavior of root processe... |
| CVE-2020-28013 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may... |
| CVE-2020-28012 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 allows Exposure of File Descriptor to Unintended Control Sphere because rda_interpret uses a privil... |
| CVE-2020-28011 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 allows Heap-based Buffer Overflow in queue_run via two sender options: -R and -S. This may cause pr... |
| CVE-2020-28010 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 allows Out-of-bounds Write because the main function, while setuid root, copies the current working... |
| CVE-2020-28009 | HIGH | 7.8 | 0.5% | May 6, 2021 | Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow because get_stdinput allows unbounded reads that are acc... |
| CVE-2020-28008 | HIGH | 7.8 | 0.4% | May 6, 2021 | Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory ... |
| CVE-2020-28007 | HIGH | 7.8 | 0.5% | May 6, 2021 | Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (o... |
| CVE-2020-23127 | HIGH | 8.8 | 0.8% | May 6, 2021 | Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin us... |
| CVE-2020-5013 | HIGH | 8.1 | 1.5% | May 5, 2021 | IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A r... |
| CVE-2020-4932 | HIGH | 7.8 | 0.2% | May 5, 2021 | IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for ... |
| CVE-2020-13664 | HIGH | 8.8 | 3.0% | May 5, 2021 | Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an admini... |
| CVE-2020-36334 | HIGH | 8.8 | 0.6% | May 5, 2021 | themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database. |
| CVE-2020-21999 | HIGH | 8.8 | 5.2% | May 4, 2021 | iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using de... |
| CVE-2020-27518 | HIGH | 7.8 | 0.5% | May 4, 2021 | All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the... |
| CVE-2020-35756 | HIGH | 7.5 | 1.2% | May 3, 2021 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Passwor... |
| CVE-2020-35755 | HIGH | 7.5 | 1.1% | May 3, 2021 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Inf... |
| CVE-2020-28944 | HIGH | 7.5 | 1.6% | Apr 30, 2021 | OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of d... |
| CVE-2020-7731 | HIGH | 7.5 | 1.7% | Apr 30, 2021 | This affects all versions <0.7.0 of package github.com/russellhaering/gosaml2. There is a crash on nil-pointer dereferen... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now