2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13815 | HIGH | 7.5 | 1.5% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via a loop of an indire... |
| CVE-2020-13814 | CRITICAL | 9.8 | 1.7% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a document that lacks a... |
| CVE-2020-13813 | HIGH | 7.8 | 0.8% | Jun 4, 2020 | An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted D... |
| CVE-2020-13812 | HIGH | 7.8 | 0.8% | Jun 4, 2020 | An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted D... |
| CVE-2020-13811 | HIGH | 7.8 | 2.7% | Jun 4, 2020 | An issue was discovered in Foxit Studio Photo before 3.6.6.922. It has an out-of-bounds write via a crafted TIFF file. |
| CVE-2020-13800 | MEDIUM | 6 | 0.5% | Jun 4, 2020 | ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index val... |
| CVE-2020-13791 | MEDIUM | 5.5 | 0.4% | Jun 4, 2020 | hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end... |
| CVE-2020-13765 | MEDIUM | 5.6 | 2.4% | Jun 4, 2020 | rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which all... |
| CVE-2020-13692 | HIGH | 7.7 | 4.1% | Jun 4, 2020 | PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. |
| CVE-2020-13827 | MEDIUM | 6.1 | 0.8% | Jun 4, 2020 | phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php. |
| CVE-2020-13822 | HIGH | 7.7 | 2.6% | Jun 4, 2020 | The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' byte... |
| CVE-2020-13810 | HIGH | 7.5 | 1.1% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation bypass via a modifie... |
| CVE-2020-13809 | HIGH | 7.5 | 1.5% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via long strings in ... |
| CVE-2020-13808 | HIGH | 7.5 | 1.5% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via crafted cross-re... |
| CVE-2020-13807 | HIGH | 7.5 | 1.5% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has circular reference mishandling that causes a... |
| CVE-2020-13806 | HIGH | 7.5 | 2.1% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because of JavaScript execu... |
| CVE-2020-13805 | CRITICAL | 9.8 | 1.5% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the C... |
| CVE-2020-13804 | CRITICAL | 9.8 | 1.6% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows information disclosure of a hardcoded use... |
| CVE-2020-13803 | HIGH | 7.5 | 0.7% | Jun 4, 2020 | An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signature validation bypa... |
| CVE-2020-4509 | HIGH | 7.6 | 1.5% | Jun 4, 2020 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r... |
| CVE-2020-4193 | CRITICAL | 9.8 | 1.4% | Jun 4, 2020 | IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force ... |
| CVE-2020-4191 | MEDIUM | 4.4 | 0.2% | Jun 4, 2020 | IBM Security Guardium 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hi... |
| CVE-2020-4183 | MEDIUM | 6.1 | 0.7% | Jun 4, 2020 | IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2020-9292 | CRITICAL | 9.8 | 1.5% | Jun 4, 2020 | An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated p... |
| CVE-2020-6640 | MEDIUM | 5.4 | 0.9% | Jun 4, 2020 | An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now