2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-36279HIGH7.5Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptm...
CVE-2020-36278HIGH7.5Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
CVE-2020-24984HIGH8.8An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to tri...
CVE-2020-24983HIGH8.8An issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTM...
CVE-2020-36277HIGH7.5Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in ...
CVE-2020-14987HIGH7.2An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to exec...
CVE-2020-5025HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to...
CVE-2020-5024HIGH7.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthe...
CVE-2020-1899HIGH7.5The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This ...
CVE-2020-1898HIGH7.5The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a maliciously constructe...
CVE-2020-35231HIGH8.8The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue ...
CVE-2020-35229HIGH8.8The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not p...
CVE-2020-35227HIGH7.2A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the adm...
CVE-2020-35226HIGH7.1NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sendi...
CVE-2020-35223HIGH8.8The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices...
CVE-2020-35221HIGH8.8The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was fo...
CVE-2020-27632HIGH7.5In SIMATIC MV400 family versions prior to v7.0.6, the ISN generator is initialized with a constant value and has constan...
CVE-2020-19419HIGH7.5Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive devic...
CVE-2020-19417HIGH8.8Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform ...
CVE-2020-1921HIGH7.5In the crypt function, we attempt to null terminate a buffer using the size of the input salt without validating that th...
CVE-2020-1919HIGH7.5Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument pass...
CVE-2020-1918HIGH7.5In-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking, allowing for the r...
CVE-2020-0025HIGH7.8In deletePackageVersionedInternal of PackageManagerService.java, there is a possible way to exit Screen Pinning due to a...
CVE-2020-23722HIGH8.8An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privil...
CVE-2020-13936HIGH8.8An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands w...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now