2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12104 | HIGH | 8.8 | 1.6% | May 5, 2020 | The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via... |
| CVE-2020-11737 | MEDIUM | 6.1 | 1.7% | May 5, 2020 | A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-M... |
| CVE-2020-12659 | MEDIUM | 6.7 | 0.7% | May 5, 2020 | An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write ... |
| CVE-2020-12657 | HIGH | 7.8 | 0.7% | May 5, 2020 | An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bf... |
| CVE-2020-12656 | MEDIUM | 5.5 | 0.3% | May 5, 2020 | gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through... |
| CVE-2020-12655 | MEDIUM | 5.5 | 0.5% | May 5, 2020 | An issue was discovered in xfs_agf_verify in fs/xfs/libxfs/xfs_alloc.c in the Linux kernel through 5.6.10. Attackers may... |
| CVE-2020-12653 | HIGH | 7.8 | 0.4% | May 5, 2020 | An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marv... |
| CVE-2020-12654 | HIGH | 7.1 | 1.2% | May 5, 2020 | An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wm... |
| CVE-2020-12652 | MEDIUM | 4.1 | 0.3% | May 5, 2020 | The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kernel before 5.4.14 allows local users to h... |
| CVE-2020-12649 | HIGH | 7.5 | 1.6% | May 5, 2020 | Gurbalib through 2020-04-30 allows lib/cmds/player/help.c directory traversal for reading administrative paths. |
| CVE-2020-10717 | MEDIUM | 6.5 | 0.4% | May 4, 2020 | A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version... |
| CVE-2020-10700 | MEDIUM | 5.3 | 2.0% | May 4, 2020 | A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with th... |
| CVE-2020-10686 | MEDIUM | 4.7 | 0.7% | May 4, 2020 | A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user re... |
| CVE-2020-8896 | MEDIUM | 5.9 | 0.4% | May 4, 2020 | A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 all... |
| CVE-2020-5343 | HIGH | 7.8 | 0.3% | May 4, 2020 | Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecu... |
| CVE-2020-5337 | MEDIUM | 6.1 | 0.8% | May 4, 2020 | RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attack... |
| CVE-2020-5336 | MEDIUM | 6.1 | 0.7% | May 4, 2020 | RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could... |
| CVE-2020-5335 | HIGH | 8.8 | 0.5% | May 4, 2020 | RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthentic... |
| CVE-2020-5334 | MEDIUM | 6.1 | 0.9% | May 4, 2020 | RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulner... |
| CVE-2020-5333 | MEDIUM | 4.3 | 0.8% | May 4, 2020 | RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote ... |
| CVE-2020-5332 | HIGH | 7.2 | 2.2% | May 4, 2020 | RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious us... |
| CVE-2020-5331 | MEDIUM | 5.5 | 0.7% | May 4, 2020 | RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session informatio... |
| CVE-2020-10622 | HIGH | 7.8 | 0.8% | May 4, 2020 | LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorize... |
| CVE-2020-10618 | MEDIUM | 5.5 | 0.8% | May 4, 2020 | LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unau... |
| CVE-2020-1732 | MEDIUM | 4.2 | 0.7% | May 4, 2020 | A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now