2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-11236MEDIUM5.5Memory corruption due to invalid value of total dimension in the non-histogram type KPI could lead to a denial of servic...
CVE-2020-11231MEDIUM6.7Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in tu...
CVE-2020-36312MEDIUM5.5An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory le...
CVE-2020-36311MEDIUM5.5An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of ser...
CVE-2020-36310MEDIUM5.5An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite ...
CVE-2020-13419MEDIUM5.3OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task.
CVE-2020-13418MEDIUM6.1OpenIAM before 4.2.0.3 allows XSS in the Add New User feature.
CVE-2020-36309MEDIUM5.3ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when usin...
CVE-2020-36308MEDIUM5.3Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performin...
CVE-2020-36307MEDIUM6.1Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.
CVE-2020-36306MEDIUM6.1Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.
CVE-2020-17453MEDIUM6.1WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
CVE-2020-4997MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2020-4792MEDIUM5.4IBM Edge 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i...
CVE-2020-21590MEDIUM4.3Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbit...
CVE-2020-21588MEDIUM5.5Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the...
CVE-2020-11924MEDIUM5.5An issue was discovered in WiZ Colors A60 1.14.0. Wi-Fi credentials are stored in cleartext in flash memory, which prese...
CVE-2020-11923MEDIUM5.5An issue was discovered in WiZ Colors A60 1.14.0. API credentials are locally logged.
CVE-2020-9995MEDIUM6.1An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in...
CVE-2020-9978MEDIUM4.5This issue was addressed with improved setting propagation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macO...
CVE-2020-29639MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0. Pro...
CVE-2020-29621MEDIUM5.5This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catal...
CVE-2020-29615MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11...
CVE-2020-29613MEDIUM5.5A logic issue was addressed with improved state management. This issue is fixed in iOS 14.3 and iPadOS 14.3. An enterpri...
CVE-2020-29610MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now