CVEs from 2020

3,971 normalized CVEs published or assigned in this year.

Total
3,971
critical
critical 184
high
high 576
medium
medium 738
low
low 59
% Critical
4.6%
% with KEV
3.7%
% with exploit
5.1%

Top products

  • retail_xstore_point_of_service 33
  • banking_digital_experience 30
  • primavera_unifier 29
  • retail_service_backbone 15
  • financial_services_institutional_performance_analytics 13
  • insurance_policy_administration_j2ee 11
  • communications_network_charging_and_control 10
  • enterprise_manager_base_platform 10
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-36781 unknown In the Linux kernel, the following vulnerability has been resolved: i2c: imx: fix reference leak when pm_runtime_get_sync fails In i2c_imx_xfer() and i2c_imx_remove(), the pm reference count is not…
CVE-2020-36782 unknown In the Linux kernel, the following vulnerability has been resolved: i2c: imx-lpi2c: fix reference leak when pm_runtime_get_sync fails The PM reference count is not expected to be incremented on ret…
CVE-2020-36784 unknown In the Linux kernel, the following vulnerability has been resolved: i2c: cadence: fix reference leak when pm_runtime_get_sync fails The PM reference count is not expected to be incremented on retur…
CVE-2020-36783 unknown In the Linux kernel, the following vulnerability has been resolved: i2c: img-scb: fix reference leak when pm_runtime_get_sync fails The PM reference count is not expected to be incremented on retur…
CVE-2020-36785 unknown In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the …
CVE-2020-36787 unknown In the Linux kernel, the following vulnerability has been resolved: media: aspeed: fix clock handling logic Video engine uses eclk and vclk for its clock sources and its reset control is coupled wi…
CVE-2020-3702 unknown u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the…
CVE-2020-36788 unknown In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: avoid a use-after-free when BO init fails nouveau_bo_init() is backed by ttm_bo_init() and ferries its return code b…
CVE-2020-36789 unknown In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a driver calls can_get_echo_skb() during a hardw…
CVE-2020-36790 unknown In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a memory leak We forgot to free new_model_number
CVE-2020-36791 unknown In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567 ("net_sched: fix an OOB access in cls_tcindex") I…
CVE-2020-8428 unknown fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel …
CVE-2020-16093 unknown In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::L…
CVE-2020-22570 unknown Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.
CVE-2020-14300 unknown The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorre…
CVE-2020-13977 unknown Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of t…
CVE-2020-10704 unknown A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user ca…
CVE-2020-0067 unknown In f2fs_xattr_generic_list of xattr.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. U…
CVE-2020-0030 unknown In binder_thread_release of binder.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User…
CVE-2020-0347 unknown In iptables, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no…
CVE-2020-0066 unknown In the netlink driver, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is n…
CVE-2020-0110 unknown In psi_write of psi.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User int…
CVE-2020-35269 unknown Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.
CVE-2020-0423 unknown In binder_release_work of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges …
CVE-2020-14402 unknown An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.
CVE-2020-25220 unknown The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. …
CVE-2020-25221 unknown get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page tha…
CVE-2020-25668 unknown A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
CVE-2020-27194 unknown An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values, aka CID-5b9fbeb75b6a.
CVE-2020-24916 unknown CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
CVE-2020-5991 unknown NVIDIA CUDA Toolkit, all versions prior to 11.1.1, contains a vulnerability in the NVJPEG library in which an out-of-bounds read or write operation may lead to code execution, denial of service, or i…
CVE-2020-14404 unknown An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.
CVE-2020-10931 unknown Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.
CVE-2020-36843 unknown 1y ago Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check
CVE-2020-27534 unknown 2y ago util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.T…
CVE-2020-24922 unknown 3y ago xuxueli xxl-job Cross-Site Request Forgery Vulnerability
CVE-2020-21485 unknown 3y ago Alluxio Cross Site Scripting vulnerability
CVE-2020-22755 unknown 3y ago MCMS vulnerable to arbitrary code execution via crafted thumbnail
CVE-2020-20913 unknown 3y ago Ming-Soft MCMS vulnerable to SQL injection
CVE-2020-36640 unknown 3y ago bonita-connector-webservice XML External Entity vulnerability
CVE-2020-36641 unknown 3y ago aXMLRPC XML External Entity vulnerability
CVE-2020-23622 unknown 4y ago 4thline cling uPnP protocol issue can lead to denial of service
CVE-2020-7677 unknown 4y ago thenify before 3.3.1 made use of unsafe calls to `eval`.
CVE-2020-28191 unknown 4y ago Togglz console missing cross-site request forgery (CSRF) protection
CVE-2020-10650 unknown 4y ago jackson-databind vulnerable to unsafe deserialization
CVE-2020-28865 unknown 4y ago Insufficiently Protected Credentials in PowerJob
CVE-2020-28088 unknown 4y ago Jeecg-Boot CMS arbitrary file upload vulnerability
CVE-2020-7021 unknown 4y ago Insertion of Sensitive Information into Log File in Elasticsearch
CVE-2020-29582 unknown 4y ago Incorrect Default Permissions in JetBrains Kotlin
CVE-2020-25476 unknown 4y ago Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via User Name Parameter
CVE-2020-8920 unknown 4y ago Information leak in Gerrit
CVE-2020-16971 unknown 4y ago Azure SDK for Java Security Feature Bypass Vulnerability
CVE-2020-27822 unknown 4y ago Wildfly has a memory leak vulnerability
CVE-2020-2324 unknown 4y ago XXE vulnerability in Jenkins CVS Plugin
CVE-2020-2320 unknown 4y ago Jenkins Plugin Installation Manager Tool did not verify plugin downloads
CVE-2020-2322 unknown 4y ago Missing permission checks in Jenkins Chaos Monkey Plugin
CVE-2020-2323 unknown 4y ago Missing permission checks in Jenkins Chaos Monkey Plugin
CVE-2020-2321 unknown 4y ago CSRF vulnerability in Jenkins Shelve Project Plugin
CVE-2020-2319 unknown 4y ago Password stored in plain text by Jenkins VMware Lab Manager Slaves Plugin
CVE-2020-2318 unknown 4y ago Passwords stored in plain text by Mail Commander Plugin for Jenkins-ci Plugin
CVE-2020-2311 unknown 4y ago Missing permission check in Jenkins AWS Global Configuration Plugin allows replacing plugin configuration
CVE-2020-2308 unknown 4y ago Missing Authorization in Jenkins Kubernetes Plugin
CVE-2020-2315 unknown 4y ago XXE vulnerability in Jenkins Visualworks Store Plugin
CVE-2020-2314 unknown 4y ago Password stored in plain text by Jenkins AppSpider Plugin
CVE-2020-2316 unknown 4y ago Stored XSS vulnerability in Jenkins Static Analysis Utilities Plugin
CVE-2020-2310 unknown 4y ago Missing permission checks in Jenkins Ansible Plugin allow enumerating credentials IDs
CVE-2020-2309 unknown 4y ago Missing authorization in Jenkins Kubernetes Plugin
CVE-2020-2313 unknown 4y ago Missing permission checks in Jenkins Azure Key Vault Plugin allow enumerating credentials IDs
CVE-2020-2312 unknown 4y ago Password written to the build log by Jenkins SQLPlus Script Runner Plugin
CVE-2020-2301 unknown 4y ago Authentication cache in Active Directory Jenkins Plugin allows logging in with any password
CVE-2020-2300 unknown 4y ago Improper Authentication (empty password) in Jenkins Active Directory Plugin
CVE-2020-2302 unknown 4y ago Missing permission check in Jenkins Active Directory Plugin allows accessing domain health check page
CVE-2020-2299 unknown 4y ago Improper Authentication in Jenkins Active Directory Plugin
CVE-2020-2303 unknown 4y ago CSRF vulnerability in Jenkins Active Directory Plugin
CVE-2020-2304 unknown 4y ago XXE vulnerability in Jenkins Subversion Plugin
CVE-2020-2307 unknown 4y ago Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin
CVE-2020-2306 unknown 4y ago Missing Authorization in Jenkins Mercurial Plugin
CVE-2020-2305 unknown 4y ago XXE vulnerability in Jenkins Mercurial Plugin
CVE-2020-25689 unknown 4y ago Uncontrolled Resource Consumption in WildFly
CVE-2020-10721 unknown 4y ago fabric8-maven-plugin: insecure way to construct Yaml Object leading to remote code execution
CVE-2020-2294 unknown 4y ago Missing permission checks in Jenkins Maven Cascade Release Plugin
CVE-2020-2297 unknown 4y ago Access token stored in plain text by Jenkins SMS Notification Plugin
CVE-2020-2295 unknown 4y ago CSRF vulnerability in Jenkins Maven Cascade Release Plugin
CVE-2020-2298 unknown 4y ago XXE vulnerability in Jenkins Nerrvana Plugin
CVE-2020-2289 unknown 4y ago Stored XSS vulnerability in Jenkins Active Choices Plugin
CVE-2020-2293 unknown 4y ago Arbitrary file read vulnerability in Jenkins Persona Plugin
CVE-2020-2288 unknown 4y ago Incorrect default pattern in Jenkins Audit Trail Plugin
CVE-2020-2290 unknown 4y ago Stored XSS vulnerability in Jenkins Active Choices Plugin
CVE-2020-2291 unknown 4y ago Password stored in plain text by Jenkins couchdb-statistics Plugin
CVE-2020-2296 unknown 4y ago CSRF vulnerability in Jenkins Shared Objects Plugin
CVE-2020-2292 unknown 4y ago Stored XSS vulnerability in Jenkins Release Plugin
CVE-2020-25644 unknown 4y ago Wildfly-OpenSSL memory leak flaw
CVE-2020-15840 unknown 4y ago Liferay Portal and Liferay DXP Bypass via Double Encoded URL
CVE-2020-2281 unknown 4y ago CSRF vulnerability in Jenkins Lockable Resources Plugin
CVE-2020-2280 unknown 4y ago CSRF vulnerability in Jenkins warnings Plugin allows remote code execution
CVE-2020-2283 unknown 4y ago Stored XSS vulnerability in Jenkins Liquibase Runner Plugin
CVE-2020-2284 unknown 4y ago XXE vulnerability in Jenkins Liquibase Runner Plugin
CVE-2020-2282 unknown 4y ago Missing permission check in Jenkins Implied Labels Plugin allows reconfiguring the plugin
CVE-2020-2285 unknown 4y ago Missing permission check in Jenkins Liquibase Runner Plugin allows enumerating credentials IDs
CVE-2020-2279 unknown 4y ago Sandbox bypass vulnerability in Jenkins Script Security Plugin