2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4062 | CRITICAL | 9 | 1.4% | Jun 22, 2020 | In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the ... |
| CVE-2020-14968 | CRITICAL | 9.8 | 2.9% | Jun 22, 2020 | An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does... |
| CVE-2020-14967 | CRITICAL | 9.8 | 2.6% | Jun 22, 2020 | An issue was discovered in the jsrsasign package before 8.0.18 for Node.js. Its RSA PKCS1 v1.5 decryption implementation... |
| CVE-2020-3663 | CRITICAL | 9.8 | 0.9% | Jun 22, 2020 | Buffer over-write may occur during fetching track decoder specific information if cb size exceeds buffer size in Snapdra... |
| CVE-2020-3662 | CRITICAL | 9.8 | 0.9% | Jun 22, 2020 | Buffer overflow can occur while parsing eac3 header while playing the clip which is nonstandard in Snapdragon Auto, Snap... |
| CVE-2020-3661 | CRITICAL | 9.8 | 0.9% | Jun 22, 2020 | Buffer overflow will happen while parsing mp4 clip with corrupted sample atoms values which exceeds MAX_UINT32 range due... |
| CVE-2020-3660 | CRITICAL | 9.8 | 0.9% | Jun 22, 2020 | Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto,... |
| CVE-2020-3658 | CRITICAL | 9.1 | 0.9% | Jun 22, 2020 | Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto,... |
| CVE-2020-3628 | CRITICAL | 9.8 | 1.0% | Jun 22, 2020 | Improper access due to socket opened by the logging application without specifying localhost address in Snapdragon Consu... |
| CVE-2020-3614 | CRITICAL | 9.8 | 0.7% | Jun 22, 2020 | Possible buffer overflow while copying the frame to local buffer due to lack of check of length before copying in Snapdr... |
| CVE-2020-14942 | CRITICAL | 9.8 | 1.3% | Jun 21, 2020 | Tendenci 12.0.10 allows unrestricted deserialization in apps\helpdesk\views\staff.py. |
| CVE-2020-14932 | CRITICAL | 9.8 | 1.4% | Jun 20, 2020 | compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET reques... |
| CVE-2020-14931 | CRITICAL | 9.8 | 2.6% | Jun 19, 2020 | A stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) 1.3a might allow remote WHOIS servers to ... |
| CVE-2020-8165 | CRITICAL | 9.8 | 45.7% | Jun 19, 2020 | A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attack... |
| CVE-2020-7679 | CRITICAL | 9.8 | 2.0% | Jun 19, 2020 | In all versions of package casperjs, the mergeObjects utility function is susceptible to Prototype Pollution. |
| CVE-2020-12886 | CRITICAL | 9.1 | 1.4% | Jun 18, 2020 | A buffer over-read was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing ... |
| CVE-2020-12884 | CRITICAL | 9.1 | 1.4% | Jun 18, 2020 | A buffer over-read was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing ... |
| CVE-2020-12883 | CRITICAL | 9.1 | 1.8% | Jun 18, 2020 | Buffer over-reads were discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing ... |
| CVE-2020-11503 | CRITICAL | 9.8 | 1.4% | Jun 18, 2020 | A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows ... |
| CVE-2020-13640 | CRITICAL | 9.8 | 12.7% | Jun 18, 2020 | A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute... |
| CVE-2020-3361 | CRITICAL | 9.8 | 2.4% | Jun 18, 2020 | A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker ... |
| CVE-2020-11901 | CRITICAL | 9 | 21.1% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response. |
| CVE-2020-11898 | CRITICAL | 9.1 | 18.7% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might all... |
| CVE-2020-11897 | CRITICAL | 10 | 9.1% | Jun 17, 2020 | The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets. |
| CVE-2020-11896 | CRITICAL | 10 | 37.0% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now