2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0463 | HIGH | 7.5 | 1.4% | Dec 14, 2020 | In sdp_server_handle_client_req of sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. ... |
| CVE-2020-0460 | HIGH | 7.5 | 0.7% | Dec 14, 2020 | In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates d... |
| CVE-2020-0458 | HIGH | 7.8 | 1.5% | Dec 14, 2020 | In SPDIFEncoder::writeBurstBufferBytes and related methods of SPDIFEncoder.cpp, there is a possible out of bounds write ... |
| CVE-2020-0444 | HIGH | 7.8 | 0.2% | Dec 14, 2020 | In audit_free_lsm_field of auditfilter.c, there is a possible bad kfree due to a logic error in audit_data_to_entry. Thi... |
| CVE-2020-0440 | HIGH | 7.8 | 0.2% | Dec 14, 2020 | In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a trusted virtual display due t... |
| CVE-2020-0099 | HIGH | 7.8 | 0.5% | Dec 14, 2020 | In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. T... |
| CVE-2020-28396 | HIGH | 7.3 | 0.6% | Dec 14, 2020 | A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V16), SICAM A8000 CP-8021 (All versions < V16... |
| CVE-2020-25235 | HIGH | 7.5 | 1.1% | Dec 14, 2020 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The password used for a... |
| CVE-2020-25234 | HIGH | 7.7 | 0.3% | Dec 14, 2020 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All... |
| CVE-2020-25232 | HIGH | 7.5 | 0.7% | Dec 14, 2020 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Due to the usage of an ... |
| CVE-2020-25230 | HIGH | 7.5 | 0.4% | Dec 14, 2020 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Due to the usage of an ... |
| CVE-2020-25229 | HIGH | 7.5 | 0.6% | Dec 14, 2020 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The implemented encrypt... |
| CVE-2020-15796 | HIGH | 7.5 | 1.6% | Dec 14, 2020 | A vulnerability has been identified in SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20.8), SIMATIC S7-1500... |
| CVE-2020-14368 | HIGH | 7.1 | 0.5% | Dec 14, 2020 | A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cook... |
| CVE-2020-8286 | HIGH | 7.5 | 4.6% | Dec 14, 2020 | curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verificatio... |
| CVE-2020-8285 | HIGH | 7.5 | 9.9% | Dec 14, 2020 | curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcar... |
| CVE-2020-8283 | HIGH | 8.8 | 2.6% | Dec 14, 2020 | An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SY... |
| CVE-2020-8282 | HIGH | 8.8 | 0.9% | Dec 14, 2020 | A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an a... |
| CVE-2020-8258 | HIGH | 7.5 | 1.3% | Dec 14, 2020 | Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-... |
| CVE-2020-8231 | HIGH | 7.5 | 3.7% | Dec 14, 2020 | Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data. |
| CVE-2020-8177 | HIGH | 7.8 | 1.2% | Dec 14, 2020 | curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead to... |
| CVE-2020-8169 | HIGH | 7.5 | 3.4% | Dec 14, 2020 | curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password ... |
| CVE-2020-28860 | HIGH | 8.8 | 2.2% | Dec 14, 2020 | OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating i... |
| CVE-2020-27252 | HIGH | 8.1 | 3.7% | Dec 14, 2020 | Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update sys... |
| CVE-2020-25183 | HIGH | 8.8 | 0.8% | Dec 14, 2020 | Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authentica... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now