2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12743CRITICAL9.8An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent u...
CVE-2020-5538HIGH7.8Improper Access Control in PALLET CONTROL Ver. 6.3 and earlier allows authenticated attackers to execute arbitrary code ...
CVE-2020-9315HIGH7.5** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/vers...
CVE-2020-9314MEDIUM4.8** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration c...
CVE-2020-12771MEDIUM5.5An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadloc...
CVE-2020-12770MEDIUM6.7An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failur...
CVE-2020-12769MEDIUM5.5An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via co...
CVE-2020-12768MEDIUM5.5An issue was discovered in the Linux kernel before 5.6. svm_cpu_uninit in arch/x86/kvm/svm.c has a memory leak, aka CID-...
CVE-2020-12767MEDIUM5.5exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.
CVE-2020-12766CRITICAL9.8Gnuteca 3.8 allows action=main:search:simpleSearch SQL Injection via the exemplaryStatusId parameter.
CVE-2020-12765MEDIUM5.3Solis Miolo 2.0 allows index.php?module=install&action=view&item= Directory Traversal.
CVE-2020-12764MEDIUM5.3Gnuteca 3.8 allows file.php?folder=/&file= Directory Traversal.
CVE-2020-12762HIGH7.8json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_m...
CVE-2020-12761CRITICAL9.1modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-...
CVE-2020-12637CRITICAL9.8Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled duri...
CVE-2020-12755LOW3.3fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call ev...
CVE-2020-11532CRITICAL9.8Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode...
CVE-2020-11531HIGH8.8The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the data...
CVE-2020-6616MEDIUM6.5Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (P...
CVE-2020-11530CRITICAL9.8A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in ...
CVE-2020-11006MEDIUM5.4In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed wh...
CVE-2020-12740CRITICAL9.1tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being tri...
CVE-2020-12737MEDIUM6.5An issue was discovered in Maxum Rumpus before 8.2.12 on macOS. Authenticated users can perform a path traversal using d...
CVE-2020-10690MEDIUM6.4There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cde...
CVE-2020-11541MEDIUM5.5In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now