2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3618HIGH7.8NULL exception due to accessing bad pointer while posting events on RT FIFO in Snapdragon Compute, Snapdragon Mobile, Sn...
CVE-2020-3616HIGH7.8Buffer overflow in display function due to memory copy without checking length of size using strcpy function in Snapdrag...
CVE-2020-3615CRITICAL9.8Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disas...
CVE-2020-3610HIGH7.8Possibility of double free of the drawobj that is added to the drawqueue array of the context during IOCTL commands as t...
CVE-2020-4503MEDIUM6.1IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-4431MEDIUM5.4IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-4367HIGH7.5IBM Planning Analytics Local 2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decr...
CVE-2020-4366MEDIUM6.1IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-4360MEDIUM5.4IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-13754MEDIUM6.7hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x m...
CVE-2020-13401MEDIUM6An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, c...
CVE-2020-13229HIGH8.8An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi...
CVE-2020-13228MEDIUM6.1An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.
CVE-2020-13227MEDIUM5.3An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server i...
CVE-2020-10959MEDIUM6.1resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and exter...
CVE-2020-13659LOW2.5address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
CVE-2020-10739HIGH7.5Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contain the following vulnerability when telemetry v2 is enabled: ...
CVE-2020-10703MEDIUM6.5A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in ...
CVE-2020-10136MEDIUM5.3IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP tr...
CVE-2020-9291HIGH7.8An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain eleva...
CVE-2020-13758MEDIUM6.1modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20....
CVE-2020-13757HIGH7.5Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security...
CVE-2020-13695HIGH7.2In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges t...
CVE-2020-13694HIGH8.8In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysq...
CVE-2020-13448HIGH8.8QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execut...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now