2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13632MEDIUM5.5ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
CVE-2020-13631MEDIUM5.5SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c an...
CVE-2020-13630HIGH7ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
CVE-2020-13253MEDIUM5.5sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_wr...
CVE-2020-4379HIGH7.5IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attack...
CVE-2020-4378MEDIUM4.9IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a privileged authenticated user to perform unauthorized actions u...
CVE-2020-4358MEDIUM5.4IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to emb...
CVE-2020-4357MEDIUM4.3IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a remote attacker to obtain sensitive information when a detailed...
CVE-2020-4350HIGH7.5IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attack...
CVE-2020-4349HIGH7.5IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attack...
CVE-2020-4348MEDIUM6.5IBM Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.4 could allow an authenticated GUI user to perform...
CVE-2020-4226HIGH7.5IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to info...
CVE-2020-13386HIGH7.3In SmartDraw 2020 27.0.0.0, the installer gives inherited write permissions to the Authenticated Users group on the Smar...
CVE-2020-10737MEDIUM6.3A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wh...
CVE-2020-13623HIGH7.5JerryScript 2.2.0 allows attackers to cause a denial of service (stack consumption) via a proxy operation.
CVE-2020-13622HIGH7.5JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a P...
CVE-2020-13616MEDIUM5.9The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification.
CVE-2020-13615MEDIUM5.9lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.
CVE-2020-13614MEDIUM5.9An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
CVE-2020-9046HIGH7.8A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user ...
CVE-2020-6831CRITICAL9.8A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruptio...
CVE-2020-6830HIGH7.5For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridgin...
CVE-2020-12392MEDIUM5.5The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can b...
CVE-2020-12391HIGH7.5Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed t...
CVE-2020-12390CRITICAL9.8Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now