2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13632 | MEDIUM | 5.5 | 0.6% | May 27, 2020 | ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query. |
| CVE-2020-13631 | MEDIUM | 5.5 | 0.6% | May 27, 2020 | SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c an... |
| CVE-2020-13630 | HIGH | 7 | 1.0% | May 27, 2020 | ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature. |
| CVE-2020-13253 | MEDIUM | 5.5 | 0.4% | May 27, 2020 | sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_wr... |
| CVE-2020-4379 | HIGH | 7.5 | 0.8% | May 27, 2020 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attack... |
| CVE-2020-4378 | MEDIUM | 4.9 | 0.9% | May 27, 2020 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a privileged authenticated user to perform unauthorized actions u... |
| CVE-2020-4358 | MEDIUM | 5.4 | 0.6% | May 27, 2020 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to emb... |
| CVE-2020-4357 | MEDIUM | 4.3 | 1.0% | May 27, 2020 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a remote attacker to obtain sensitive information when a detailed... |
| CVE-2020-4350 | HIGH | 7.5 | 0.8% | May 27, 2020 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attack... |
| CVE-2020-4349 | HIGH | 7.5 | 0.8% | May 27, 2020 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attack... |
| CVE-2020-4348 | MEDIUM | 6.5 | 0.8% | May 27, 2020 | IBM Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.4 could allow an authenticated GUI user to perform... |
| CVE-2020-4226 | HIGH | 7.5 | 1.3% | May 27, 2020 | IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to info... |
| CVE-2020-13386 | HIGH | 7.3 | 0.3% | May 27, 2020 | In SmartDraw 2020 27.0.0.0, the installer gives inherited write permissions to the Authenticated Users group on the Smar... |
| CVE-2020-10737 | MEDIUM | 6.3 | 0.3% | May 27, 2020 | A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wh... |
| CVE-2020-13623 | HIGH | 7.5 | 1.2% | May 27, 2020 | JerryScript 2.2.0 allows attackers to cause a denial of service (stack consumption) via a proxy operation. |
| CVE-2020-13622 | HIGH | 7.5 | 1.3% | May 27, 2020 | JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a P... |
| CVE-2020-13616 | MEDIUM | 5.9 | 0.9% | May 26, 2020 | The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification. |
| CVE-2020-13615 | MEDIUM | 5.9 | 0.6% | May 26, 2020 | lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates. |
| CVE-2020-13614 | MEDIUM | 5.9 | 1.9% | May 26, 2020 | An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification. |
| CVE-2020-9046 | HIGH | 7.8 | 0.3% | May 26, 2020 | A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user ... |
| CVE-2020-6831 | CRITICAL | 9.8 | 5.8% | May 26, 2020 | A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruptio... |
| CVE-2020-6830 | HIGH | 7.5 | 0.9% | May 26, 2020 | For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridgin... |
| CVE-2020-12392 | MEDIUM | 5.5 | 0.3% | May 26, 2020 | The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can b... |
| CVE-2020-12391 | HIGH | 7.5 | 1.4% | May 26, 2020 | Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed t... |
| CVE-2020-12390 | CRITICAL | 9.8 | 1.6% | May 26, 2020 | Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now