2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-35492HIGH7.8A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can pro...
CVE-2020-27827HIGH7.5A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when al...
CVE-2020-26155HIGH7.8Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions fo...
CVE-2020-35455HIGH7.8The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Sha...
CVE-2020-28873HIGH7.5Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user ...
CVE-2020-17525HIGH7.5Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRela...
CVE-2020-13924HIGH7.5In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and trav...
CVE-2020-11309HIGH7.8Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in S...
CVE-2020-11290HIGH7Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon ...
CVE-2020-11228HIGH7.8Part of RPM region was not protected from xblSec itself due to improper policy and leads to unprivileged access in Snapd...
CVE-2020-11226HIGH7.5Out of bound memory read in Data modem while unpacking data due to lack of offset length check in Snapdragon Auto, Snapd...
CVE-2020-11218HIGH7.5Denial of service in baseband when NW configures LTE betaOffset-RI-Index due to lack of data validation in Snapdragon Au...
CVE-2020-24263HIGH8.8Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code...
CVE-2020-29553HIGH8.8The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into v...
CVE-2020-29555HIGH8.1The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary file...
CVE-2020-24985HIGH8.1An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuP...
CVE-2020-28385HIGH7.8A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2021 (All Versions < ...
CVE-2020-25241HIGH7.5A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the aff...
CVE-2020-25240HIGH8.8A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can acces...
CVE-2020-25239HIGH8.8A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow una...
CVE-2020-4184HIGH7.3IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, wh...
CVE-2020-35682HIGH8.8Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
CVE-2020-4831HIGH7.5IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 uses weaker than expected cryptographic algorithms that could allow an a...
CVE-2020-36281HIGH7.5Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.
CVE-2020-36280HIGH7.5Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now