2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4420HIGH7.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthe...
CVE-2020-4414MEDIUM4.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local at...
CVE-2020-4387MEDIUM4.7IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us...
CVE-2020-4386MEDIUM4.7IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us...
CVE-2020-4376MEDIUM6.5IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow an attacker to cause a denial of service ca...
CVE-2020-4363HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buf...
CVE-2020-4355MEDIUM5.3IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a den...
CVE-2020-13383HIGH7.5openSIS through 7.4 allows Directory Traversal.
CVE-2020-13382CRITICAL9.1openSIS through 7.4 has Incorrect Access Control.
CVE-2020-13381CRITICAL9.8openSIS through 7.4 allows SQL Injection.
CVE-2020-13380CRITICAL9.8openSIS before 7.4 allows SQL Injection.
CVE-2020-12605HIGH7.5Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers...
CVE-2020-12604HIGH7.5Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 cli...
CVE-2020-7689HIGH7.5Data is truncated wrong when its length is greater than 255 bytes.
CVE-2020-5900HIGH8.8In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for...
CVE-2020-12603HIGH7.5Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when proxying HTTP/2 requests or...
CVE-2020-6261MEDIUM5.3SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, ...
CVE-2020-15478HIGH7.5The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
CVE-2020-15476HIGH7.5In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protoc...
CVE-2020-15475CRITICAL9.8In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-aft...
CVE-2020-15474CRITICAL9.8In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.
CVE-2020-15473CRITICAL9.1In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/...
CVE-2020-15472CRITICAL9.1In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/proto...
CVE-2020-15471CRITICAL9.1In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_in...
CVE-2020-15470MEDIUM5.5ffjpeg through 2020-02-24 has a heap-based buffer overflow in jfif_decode in jfif.c.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now