2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13815HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via a loop of an indire...
CVE-2020-13814CRITICAL9.8An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a document that lacks a...
CVE-2020-13813HIGH7.8An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted D...
CVE-2020-13812HIGH7.8An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted D...
CVE-2020-13811HIGH7.8An issue was discovered in Foxit Studio Photo before 3.6.6.922. It has an out-of-bounds write via a crafted TIFF file.
CVE-2020-13800MEDIUM6ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index val...
CVE-2020-13791MEDIUM5.5hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end...
CVE-2020-13765MEDIUM5.6rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which all...
CVE-2020-13692HIGH7.7PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
CVE-2020-13827MEDIUM6.1phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.
CVE-2020-13822HIGH7.7The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' byte...
CVE-2020-13810HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation bypass via a modifie...
CVE-2020-13809HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via long strings in ...
CVE-2020-13808HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via crafted cross-re...
CVE-2020-13807HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has circular reference mishandling that causes a...
CVE-2020-13806HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because of JavaScript execu...
CVE-2020-13805CRITICAL9.8An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the C...
CVE-2020-13804CRITICAL9.8An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows information disclosure of a hardcoded use...
CVE-2020-13803HIGH7.5An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signature validation bypa...
CVE-2020-4509HIGH7.6IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r...
CVE-2020-4193CRITICAL9.8IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force ...
CVE-2020-4191MEDIUM4.4IBM Security Guardium 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hi...
CVE-2020-4183MEDIUM6.1IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2020-9292CRITICAL9.8An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated p...
CVE-2020-6640MEDIUM5.4An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now