2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4420 | HIGH | 7.5 | 2.4% | Jul 1, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthe... |
| CVE-2020-4414 | MEDIUM | 4.4 | 0.3% | Jul 1, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local at... |
| CVE-2020-4387 | MEDIUM | 4.7 | 0.2% | Jul 1, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us... |
| CVE-2020-4386 | MEDIUM | 4.7 | 0.2% | Jul 1, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us... |
| CVE-2020-4376 | MEDIUM | 6.5 | 1.1% | Jul 1, 2020 | IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow an attacker to cause a denial of service ca... |
| CVE-2020-4363 | HIGH | 7.8 | 0.5% | Jul 1, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buf... |
| CVE-2020-4355 | MEDIUM | 5.3 | 2.2% | Jul 1, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a den... |
| CVE-2020-13383 | HIGH | 7.5 | 69.6% | Jul 1, 2020 | openSIS through 7.4 allows Directory Traversal. |
| CVE-2020-13382 | CRITICAL | 9.1 | 52.8% | Jul 1, 2020 | openSIS through 7.4 has Incorrect Access Control. |
| CVE-2020-13381 | CRITICAL | 9.8 | 59.0% | Jul 1, 2020 | openSIS through 7.4 allows SQL Injection. |
| CVE-2020-13380 | CRITICAL | 9.8 | 2.4% | Jul 1, 2020 | openSIS before 7.4 allows SQL Injection. |
| CVE-2020-12605 | HIGH | 7.5 | 1.4% | Jul 1, 2020 | Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers... |
| CVE-2020-12604 | HIGH | 7.5 | 1.7% | Jul 1, 2020 | Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 cli... |
| CVE-2020-7689 | HIGH | 7.5 | 0.8% | Jul 1, 2020 | Data is truncated wrong when its length is greater than 255 bytes. |
| CVE-2020-5900 | HIGH | 8.8 | 0.5% | Jul 1, 2020 | In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for... |
| CVE-2020-12603 | HIGH | 7.5 | 1.4% | Jul 1, 2020 | Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when proxying HTTP/2 requests or... |
| CVE-2020-6261 | MEDIUM | 5.3 | 0.8% | Jul 1, 2020 | SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, ... |
| CVE-2020-15478 | HIGH | 7.5 | 4.7% | Jul 1, 2020 | The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors. |
| CVE-2020-15476 | HIGH | 7.5 | 2.1% | Jul 1, 2020 | In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protoc... |
| CVE-2020-15475 | CRITICAL | 9.8 | 1.2% | Jul 1, 2020 | In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-aft... |
| CVE-2020-15474 | CRITICAL | 9.8 | 1.2% | Jul 1, 2020 | In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c. |
| CVE-2020-15473 | CRITICAL | 9.1 | 1.3% | Jul 1, 2020 | In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/... |
| CVE-2020-15472 | CRITICAL | 9.1 | 1.5% | Jul 1, 2020 | In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/proto... |
| CVE-2020-15471 | CRITICAL | 9.1 | 1.3% | Jul 1, 2020 | In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_in... |
| CVE-2020-15470 | MEDIUM | 5.5 | 0.7% | Jul 1, 2020 | ffjpeg through 2020-02-24 has a heap-based buffer overflow in jfif_decode in jfif.c. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now