2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12743 | CRITICAL | 9.8 | 1.5% | May 11, 2020 | An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent u... |
| CVE-2020-5538 | HIGH | 7.8 | 0.4% | May 11, 2020 | Improper Access Control in PALLET CONTROL Ver. 6.3 and earlier allows authenticated attackers to execute arbitrary code ... |
| CVE-2020-9315 | HIGH | 7.5 | 81.8% | May 10, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/vers... |
| CVE-2020-9314 | MEDIUM | 4.8 | 1.3% | May 10, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration c... |
| CVE-2020-12771 | MEDIUM | 5.5 | 0.5% | May 9, 2020 | An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadloc... |
| CVE-2020-12770 | MEDIUM | 6.7 | 0.6% | May 9, 2020 | An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failur... |
| CVE-2020-12769 | MEDIUM | 5.5 | 0.7% | May 9, 2020 | An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via co... |
| CVE-2020-12768 | MEDIUM | 5.5 | 0.4% | May 9, 2020 | An issue was discovered in the Linux kernel before 5.6. svm_cpu_uninit in arch/x86/kvm/svm.c has a memory leak, aka CID-... |
| CVE-2020-12767 | MEDIUM | 5.5 | 0.5% | May 9, 2020 | exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error. |
| CVE-2020-12766 | CRITICAL | 9.8 | 1.0% | May 9, 2020 | Gnuteca 3.8 allows action=main:search:simpleSearch SQL Injection via the exemplaryStatusId parameter. |
| CVE-2020-12765 | MEDIUM | 5.3 | 1.3% | May 9, 2020 | Solis Miolo 2.0 allows index.php?module=install&action=view&item= Directory Traversal. |
| CVE-2020-12764 | MEDIUM | 5.3 | 1.3% | May 9, 2020 | Gnuteca 3.8 allows file.php?folder=/&file= Directory Traversal. |
| CVE-2020-12762 | HIGH | 7.8 | 1.9% | May 9, 2020 | json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_m... |
| CVE-2020-12761 | CRITICAL | 9.1 | 1.6% | May 9, 2020 | modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-... |
| CVE-2020-12637 | CRITICAL | 9.8 | 0.7% | May 9, 2020 | Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled duri... |
| CVE-2020-12755 | LOW | 3.3 | 0.4% | May 9, 2020 | fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call ev... |
| CVE-2020-11532 | CRITICAL | 9.8 | 77.5% | May 8, 2020 | Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode... |
| CVE-2020-11531 | HIGH | 8.8 | 13.7% | May 8, 2020 | The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the data... |
| CVE-2020-6616 | MEDIUM | 6.5 | 0.7% | May 8, 2020 | Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (P... |
| CVE-2020-11530 | CRITICAL | 9.8 | 95.7% | May 8, 2020 | A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in ... |
| CVE-2020-11006 | MEDIUM | 5.4 | 0.6% | May 8, 2020 | In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed wh... |
| CVE-2020-12740 | CRITICAL | 9.1 | 1.7% | May 8, 2020 | tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being tri... |
| CVE-2020-12737 | MEDIUM | 6.5 | 1.1% | May 8, 2020 | An issue was discovered in Maxum Rumpus before 8.2.12 on macOS. Authenticated users can perform a path traversal using d... |
| CVE-2020-10690 | MEDIUM | 6.4 | 0.4% | May 8, 2020 | There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cde... |
| CVE-2020-11541 | MEDIUM | 5.5 | 0.3% | May 8, 2020 | In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now