2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36279 | HIGH | 7.5 | 2.6% | Mar 12, 2021 | Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptm... |
| CVE-2020-36278 | HIGH | 7.5 | 2.9% | Mar 12, 2021 | Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c. |
| CVE-2020-24984 | HIGH | 8.8 | 0.6% | Mar 11, 2021 | An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to tri... |
| CVE-2020-24983 | HIGH | 8.8 | 0.6% | Mar 11, 2021 | An issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTM... |
| CVE-2020-36277 | HIGH | 7.5 | 2.4% | Mar 11, 2021 | Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in ... |
| CVE-2020-14987 | HIGH | 7.2 | 3.5% | Mar 11, 2021 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to exec... |
| CVE-2020-5025 | HIGH | 7.8 | 0.6% | Mar 11, 2021 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to... |
| CVE-2020-5024 | HIGH | 7.5 | 2.0% | Mar 11, 2021 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthe... |
| CVE-2020-1899 | HIGH | 7.5 | 1.2% | Mar 11, 2021 | The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This ... |
| CVE-2020-1898 | HIGH | 7.5 | 1.2% | Mar 11, 2021 | The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a maliciously constructe... |
| CVE-2020-35231 | HIGH | 8.8 | 1.1% | Mar 10, 2021 | The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue ... |
| CVE-2020-35229 | HIGH | 8.8 | 0.8% | Mar 10, 2021 | The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not p... |
| CVE-2020-35227 | HIGH | 7.2 | 1.1% | Mar 10, 2021 | A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the adm... |
| CVE-2020-35226 | HIGH | 7.1 | 0.6% | Mar 10, 2021 | NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sendi... |
| CVE-2020-35223 | HIGH | 8.8 | 0.6% | Mar 10, 2021 | The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices... |
| CVE-2020-35221 | HIGH | 8.8 | 0.5% | Mar 10, 2021 | The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was fo... |
| CVE-2020-27632 | HIGH | 7.5 | 1.2% | Mar 10, 2021 | In SIMATIC MV400 family versions prior to v7.0.6, the ISN generator is initialized with a constant value and has constan... |
| CVE-2020-19419 | HIGH | 7.5 | 3.0% | Mar 10, 2021 | Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive devic... |
| CVE-2020-19417 | HIGH | 8.8 | 2.7% | Mar 10, 2021 | Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform ... |
| CVE-2020-1921 | HIGH | 7.5 | 1.2% | Mar 10, 2021 | In the crypt function, we attempt to null terminate a buffer using the size of the input salt without validating that th... |
| CVE-2020-1919 | HIGH | 7.5 | 1.2% | Mar 10, 2021 | Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument pass... |
| CVE-2020-1918 | HIGH | 7.5 | 1.2% | Mar 10, 2021 | In-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking, allowing for the r... |
| CVE-2020-0025 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In deletePackageVersionedInternal of PackageManagerService.java, there is a possible way to exit Screen Pinning due to a... |
| CVE-2020-23722 | HIGH | 8.8 | 1.0% | Mar 10, 2021 | An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privil... |
| CVE-2020-13936 | HIGH | 8.8 | 22.7% | Mar 10, 2021 | An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands w... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now