2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3618 | HIGH | 7.8 | 0.2% | Jun 2, 2020 | NULL exception due to accessing bad pointer while posting events on RT FIFO in Snapdragon Compute, Snapdragon Mobile, Sn... |
| CVE-2020-3616 | HIGH | 7.8 | 0.2% | Jun 2, 2020 | Buffer overflow in display function due to memory copy without checking length of size using strcpy function in Snapdrag... |
| CVE-2020-3615 | CRITICAL | 9.8 | 0.8% | Jun 2, 2020 | Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disas... |
| CVE-2020-3610 | HIGH | 7.8 | 0.2% | Jun 2, 2020 | Possibility of double free of the drawobj that is added to the drawqueue array of the context during IOCTL commands as t... |
| CVE-2020-4503 | MEDIUM | 6.1 | 0.8% | Jun 2, 2020 | IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2020-4431 | MEDIUM | 5.4 | 0.6% | Jun 2, 2020 | IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2020-4367 | HIGH | 7.5 | 0.8% | Jun 2, 2020 | IBM Planning Analytics Local 2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decr... |
| CVE-2020-4366 | MEDIUM | 6.1 | 0.7% | Jun 2, 2020 | IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2020-4360 | MEDIUM | 5.4 | 0.7% | Jun 2, 2020 | IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2020-13754 | MEDIUM | 6.7 | 0.4% | Jun 2, 2020 | hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x m... |
| CVE-2020-13401 | MEDIUM | 6 | 2.8% | Jun 2, 2020 | An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, c... |
| CVE-2020-13229 | HIGH | 8.8 | 1.6% | Jun 2, 2020 | An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi... |
| CVE-2020-13228 | MEDIUM | 6.1 | 3.1% | Jun 2, 2020 | An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter. |
| CVE-2020-13227 | MEDIUM | 5.3 | 1.9% | Jun 2, 2020 | An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server i... |
| CVE-2020-10959 | MEDIUM | 6.1 | 1.4% | Jun 2, 2020 | resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and exter... |
| CVE-2020-13659 | LOW | 2.5 | 0.4% | Jun 2, 2020 | address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer. |
| CVE-2020-10739 | HIGH | 7.5 | 2.3% | Jun 2, 2020 | Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contain the following vulnerability when telemetry v2 is enabled: ... |
| CVE-2020-10703 | MEDIUM | 6.5 | 2.4% | Jun 2, 2020 | A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in ... |
| CVE-2020-10136 | MEDIUM | 5.3 | 26.5% | Jun 2, 2020 | IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP tr... |
| CVE-2020-9291 | HIGH | 7.8 | 0.5% | Jun 1, 2020 | An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain eleva... |
| CVE-2020-13758 | MEDIUM | 6.1 | 0.9% | Jun 1, 2020 | modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.... |
| CVE-2020-13757 | HIGH | 7.5 | 1.4% | Jun 1, 2020 | Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security... |
| CVE-2020-13695 | HIGH | 7.2 | 1.4% | Jun 1, 2020 | In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges t... |
| CVE-2020-13694 | HIGH | 8.8 | 1.7% | Jun 1, 2020 | In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysq... |
| CVE-2020-13448 | HIGH | 8.8 | 17.8% | Jun 1, 2020 | QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execut... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now