CVEs from 2020
Total
4,160
critical
critical 193
high
high 470
medium
medium 675
low
low 56
% Critical
4.6%
% with KEV
3.5%
% with exploit
3.6%
Top products
- banking_digital_experience 30
- retail_xstore_point_of_service 28
- primavera_unifier 27
- retail_service_backbone 15
- financial_services_institutional_performance_analytics 10
- communications_network_charging_and_control 10
- communications_contacts_server 9
- agile_plm 8
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2020-35730 | high | — | 9.5 | 3y ago | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference el… | |
| CVE-2020-6418 | high | — | 9.5 | 5y ago | multiple issues in chromium | |
| CVE-2020-16017 | high | — | 9.5 | 6y ago | Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. | |
| CVE-2020-16013 | high | — | 9.5 | 6y ago | Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could… | |
| CVE-2020-15999 | high | — | 9.5 | 6y ago | Important: freetype security update | |
| CVE-2020-1472 | medium | — | 7.0 | 5y ago | Moderate: samba security, bug fix, and enhancement update | |
| CVE-2020-36193 | medium | — | 7.0 | 5y ago | Moderate: php:7.4 security update | |
| CVE-2020-28949 | medium | — | 7.0 | 6y ago | Moderate: php:7.4 security update | |
| CVE-2020-1938 | medium | — | 7.0 | 6y ago | Improper Privilege Management in Tomcat | |
| CVE-2020-11023 | medium | — | 7.0 | 6y ago | Potential XSS vulnerability in jQuery | |
| CVE-2020-13965 | unknown | — | 1.5 | 2y ago | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. | |
| CVE-2020-12641 | unknown | — | 1.5 | 3y ago | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. | |
| CVE-2020-7961 | unknown | — | 1.5 | 4y ago | Deserialization of Untrusted Data in Liferay Portal | |
| CVE-2020-17530 | unknown | — | 1.5 | 4y ago | Remote code execution in Apache Struts | |
| CVE-2020-0041 | unknown | — | 1.5 | 5y ago | In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges n… | |
| CVE-2020-17519 | unknown | — | 1.5 | 6y ago | Path Traversal in Apache Flink | |
| CVE-2020-1956 | unknown | — | 1.5 | 6y ago | Command Injection in Kylin | |
| CVE-2020-5410 | unknown | — | 1.5 | 6y ago | Directory traversal attack in Spring Cloud Config | |
| CVE-2020-10199 | unknown | — | 1.5 | 6y ago | Nexus Repository Manager 3 - Remote Code Execution |