2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35492 | HIGH | 7.8 | 1.1% | Mar 18, 2021 | A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can pro... |
| CVE-2020-27827 | HIGH | 7.5 | 3.2% | Mar 18, 2021 | A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when al... |
| CVE-2020-26155 | HIGH | 7.8 | 0.4% | Mar 18, 2021 | Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions fo... |
| CVE-2020-35455 | HIGH | 7.8 | 0.2% | Mar 17, 2021 | The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Sha... |
| CVE-2020-28873 | HIGH | 7.5 | 0.9% | Mar 17, 2021 | Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user ... |
| CVE-2020-17525 | HIGH | 7.5 | 37.5% | Mar 17, 2021 | Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRela... |
| CVE-2020-13924 | HIGH | 7.5 | 4.0% | Mar 17, 2021 | In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and trav... |
| CVE-2020-11309 | HIGH | 7.8 | 0.2% | Mar 17, 2021 | Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in S... |
| CVE-2020-11290 | HIGH | 7 | 0.2% | Mar 17, 2021 | Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon ... |
| CVE-2020-11228 | HIGH | 7.8 | 0.2% | Mar 17, 2021 | Part of RPM region was not protected from xblSec itself due to improper policy and leads to unprivileged access in Snapd... |
| CVE-2020-11226 | HIGH | 7.5 | 0.9% | Mar 17, 2021 | Out of bound memory read in Data modem while unpacking data due to lack of offset length check in Snapdragon Auto, Snapd... |
| CVE-2020-11218 | HIGH | 7.5 | 0.8% | Mar 17, 2021 | Denial of service in baseband when NW configures LTE betaOffset-RI-Index due to lack of data validation in Snapdragon Au... |
| CVE-2020-24263 | HIGH | 8.8 | 1.6% | Mar 16, 2021 | Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code... |
| CVE-2020-29553 | HIGH | 8.8 | 1.4% | Mar 15, 2021 | The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into v... |
| CVE-2020-29555 | HIGH | 8.1 | 2.9% | Mar 15, 2021 | The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary file... |
| CVE-2020-24985 | HIGH | 8.1 | 1.1% | Mar 15, 2021 | An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuP... |
| CVE-2020-28385 | HIGH | 7.8 | 1.5% | Mar 15, 2021 | A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2021 (All Versions < ... |
| CVE-2020-25241 | HIGH | 7.5 | 1.0% | Mar 15, 2021 | A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the aff... |
| CVE-2020-25240 | HIGH | 8.8 | 0.9% | Mar 15, 2021 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can acces... |
| CVE-2020-25239 | HIGH | 8.8 | 0.9% | Mar 15, 2021 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow una... |
| CVE-2020-4184 | HIGH | 7.3 | 0.8% | Mar 15, 2021 | IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, wh... |
| CVE-2020-35682 | HIGH | 8.8 | 7.2% | Mar 13, 2021 | Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login). |
| CVE-2020-4831 | HIGH | 7.5 | 0.8% | Mar 12, 2021 | IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 uses weaker than expected cryptographic algorithms that could allow an a... |
| CVE-2020-36281 | HIGH | 7.5 | 2.9% | Mar 12, 2021 | Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c. |
| CVE-2020-36280 | HIGH | 7.5 | 2.4% | Mar 12, 2021 | Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now