2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11236 | MEDIUM | 5.5 | 0.4% | Apr 7, 2021 | Memory corruption due to invalid value of total dimension in the non-histogram type KPI could lead to a denial of servic... |
| CVE-2020-11231 | MEDIUM | 6.7 | 0.2% | Apr 7, 2021 | Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in tu... |
| CVE-2020-36312 | MEDIUM | 5.5 | 0.3% | Apr 7, 2021 | An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory le... |
| CVE-2020-36311 | MEDIUM | 5.5 | 0.3% | Apr 7, 2021 | An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of ser... |
| CVE-2020-36310 | MEDIUM | 5.5 | 0.3% | Apr 7, 2021 | An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite ... |
| CVE-2020-13419 | MEDIUM | 5.3 | 1.2% | Apr 6, 2021 | OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task. |
| CVE-2020-13418 | MEDIUM | 6.1 | 0.6% | Apr 6, 2021 | OpenIAM before 4.2.0.3 allows XSS in the Add New User feature. |
| CVE-2020-36309 | MEDIUM | 5.3 | 1.3% | Apr 6, 2021 | ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when usin... |
| CVE-2020-36308 | MEDIUM | 5.3 | 1.0% | Apr 6, 2021 | Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performin... |
| CVE-2020-36307 | MEDIUM | 6.1 | 0.7% | Apr 6, 2021 | Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links. |
| CVE-2020-36306 | MEDIUM | 6.1 | 0.7% | Apr 6, 2021 | Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field. |
| CVE-2020-17453 | MEDIUM | 6.1 | 26.1% | Apr 5, 2021 | WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. |
| CVE-2020-4997 | MEDIUM | 5.4 | 0.5% | Apr 5, 2021 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2020-4792 | MEDIUM | 5.4 | 0.5% | Apr 5, 2021 | IBM Edge 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i... |
| CVE-2020-21590 | MEDIUM | 4.3 | 1.3% | Apr 2, 2021 | Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbit... |
| CVE-2020-21588 | MEDIUM | 5.5 | 0.3% | Apr 2, 2021 | Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the... |
| CVE-2020-11924 | MEDIUM | 5.5 | 0.3% | Apr 2, 2021 | An issue was discovered in WiZ Colors A60 1.14.0. Wi-Fi credentials are stored in cleartext in flash memory, which prese... |
| CVE-2020-11923 | MEDIUM | 5.5 | 0.3% | Apr 2, 2021 | An issue was discovered in WiZ Colors A60 1.14.0. API credentials are locally logged. |
| CVE-2020-9995 | MEDIUM | 6.1 | 0.6% | Apr 2, 2021 | An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in... |
| CVE-2020-9978 | MEDIUM | 4.5 | 0.5% | Apr 2, 2021 | This issue was addressed with improved setting propagation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macO... |
| CVE-2020-29639 | MEDIUM | 5.5 | 0.7% | Apr 2, 2021 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0. Pro... |
| CVE-2020-29621 | MEDIUM | 5.5 | 0.3% | Apr 2, 2021 | This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catal... |
| CVE-2020-29615 | MEDIUM | 5.5 | 0.8% | Apr 2, 2021 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11... |
| CVE-2020-29613 | MEDIUM | 5.5 | 0.6% | Apr 2, 2021 | A logic issue was addressed with improved state management. This issue is fixed in iOS 14.3 and iPadOS 14.3. An enterpri... |
| CVE-2020-29610 | MEDIUM | 5.5 | 0.8% | Apr 2, 2021 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now