CVEs from 2020

4,156 normalized CVEs published or assigned in this year.

Total
4,156
critical
critical 193
high
high 470
medium
medium 674
low
low 57
% Critical
4.6%
% with KEV
3.5%
% with exploit
3.6%

Top products

  • banking_digital_experience 30
  • retail_xstore_point_of_service 28
  • primavera_unifier 27
  • retail_service_backbone 15
  • financial_services_institutional_performance_analytics 10
  • communications_network_charging_and_control 10
  • communications_contacts_server 9
  • agile_plm 8
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2020-2804 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-14550 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-14623 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-14632 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-14643 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-14697 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2577 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2589 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2588 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2686 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2762 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2759 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2901 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2765 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2774 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2893 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-14539 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-14575 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-14586 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-14651 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-14631 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-14799 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxdebianalmalinux
CVE-2020-2679 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2694 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2895 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2896 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2898 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2814 high 8.0 6y ago Important: mariadb:10.3 security, bug fix, and enhancement update rockylinuxalmalinux
CVE-2020-2760 high 8.0 6y ago Important: mariadb:10.3 security, bug fix, and enhancement update rockylinuxalmalinux
CVE-2020-2780 high 8.0 6y ago Important: mariadb:10.3 security, bug fix, and enhancement update rockylinuxalmalinux
CVE-2020-2763 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2574 high 8.0 6y ago Important: mariadb:10.3 security, bug fix, and enhancement update suserockylinuxalmalinux
CVE-2020-14614 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-14680 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2660 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-2926 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-14641 high 8.0 6y ago Important: mysql:8.0 security update rockylinuxalmalinux
CVE-2020-11538 high 8.0 6y ago In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311. suserockylinuxdebianpython
CVE-2020-8172 high 8.0 6y ago Important: nodejs:12 security update suserockylinuxdebian
CVE-2020-8174 high 8.0 6y ago Important: nodejs:12 security update suserockylinuxdebian
CVE-2020-11080 high 8.0 6y ago Important: nodejs:12 security update suserockylinuxdebian
CVE-2020-9402 high 8.0 6y ago Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a sui… archsusedebianpython
CVE-2020-9484 high 8.0 6y ago Potential remote code execution in Apache Tomcat archsusedebianjava
CVE-2020-11945 high 8.0 6y ago Important: squid:4 security update archsuserockylinuxdebian
CVE-2020-1967 high 8.0 6y ago Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signat… archsusedebianrust
CVE-2020-7039 high 8.0 6y ago Important: container-tools:rhel8 security, bug fix, and enhancement update susedebianrockylinux
CVE-2020-1711 high 8.0 6y ago Important: virt:rhel security and bug fix update suserockylinuxdebian
CVE-2020-8608 high 8.0 6y ago Important: virt:rhel security update susedebianrockylinux
CVE-2020-7598 high 8.0 6y ago Important: nodejs:12 security update suserockylinuxdebiannpm
CVE-2020-5313 high 8.0 6y ago libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow. suserockylinuxdebianpython
CVE-2020-10531 high 8.0 6y ago Important: nodejs:10 security update susedebianrockylinux
CVE-2020-8597 high 8.0 6y ago Important: ppp security update archsuserockylinuxdebian
CVE-2020-37247 high 7.8 7.8 12d ago Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers …
CVE-2020-37232 high 7.8 7.8 12d ago Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Atta…
CVE-2020-37231 high 7.8 7.8 12d ago Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Atta…
CVE-2020-37230 high 7.8 7.8 12d ago Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path…
CVE-2020-37229 high 7.8 7.8 12d ago OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unqu…
CVE-2020-37223 high 7.8 7.8 15d ago IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a maliciou…
CVE-2020-10648 high 7.8 7.8 6y ago Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default con… archsusedebian
CVE-2020-37245 high 7.5 7.5 12d ago Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequ…
CVE-2020-37220 high 7.5 7.5 15d ago Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can quer…
CVE-2020-37219 high 7.5 7.5 15d ago Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET reques…
CVE-2020-37130 high 7.5 7.5 4mo ago Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 byte…
CVE-2020-37015 high 7.5 7.5 4mo ago The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file p…
CVE-2020-37011 high 7.5 7.5 4mo ago Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially cr…
CVE-2020-25720 high 7.5 7.5 2y ago A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-se… susedebian
CVE-2020-37222 high 7.2 7.2 15d ago Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs reply endpoi…
CVE-2020-37226 high 7.1 7.1 15d ago Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att…
CVE-2020-37224 high 7.1 7.1 15d ago Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att…
CVE-2020-1472 medium 7.0 5y ago Moderate: samba security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2020-36193 medium 7.0 5y ago Moderate: php:7.4 security update archsuserockylinuxdebian+1
CVE-2020-17103 high 7.0 7.0 6y ago Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability windows
CVE-2020-28949 medium 7.0 6y ago Moderate: php:7.4 security update rockylinuxdebianphp
CVE-2020-1938 medium 7.0 6y ago Improper Privilege Management in Tomcat suserockylinuxdebianjava
CVE-2020-11023 medium 7.0 6y ago Moderate: gcc security update redhatrockylinuxsusedebian+6
CVE-2020-37240 medium 6.4 6.4 12d ago Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can ins…
CVE-2020-37238 medium 6.4 6.4 12d ago CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers…
CVE-2020-37237 medium 6.4 6.4 12d ago Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers wi…
CVE-2020-37236 medium 6.4 6.4 12d ago NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news additio…
CVE-2020-37235 medium 6.4 6.4 12d ago WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parame…
CVE-2020-37233 medium 6.4 6.4 12d ago WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the fi…
CVE-2020-37225 medium 6.4 6.4 15d ago Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in…
CVE-2020-37246 medium 6.2 6.2 12d ago Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers ca…
CVE-2020-37234 medium 6.2 6.2 12d ago Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can …
CVE-2020-28621 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu… debianarch
CVE-2020-35634 medium 5.5 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_sface() s… archdebian
CVE-2020-35633 medium 5.5 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_sface() s… archdebian
CVE-2020-35631 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu… archdebian
CVE-2020-28635 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu… archdebian
CVE-2020-28634 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu… archdebian
CVE-2020-12400 medium 5.5 When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects F… debianrockylinux
CVE-2020-28633 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu… archdebian
CVE-2020-6851 medium 5.5 OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation. archsusedebian
CVE-2020-36323 medium 5.5 In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed (or the program to crash) if the borrowed string changes a… archsuserockylinuxdebian
CVE-2020-35628 medium 5.5 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->… debianarch
CVE-2020-26559 medium 5.5 multiple issues in linux archsuse
CVE-2020-28599 medium 5.5 A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code execution. An attack… archdebian
CVE-2020-21606 medium 5.5 libde265 v1.0.4 contains a heap buffer overflow fault in the put_epel_16_fallback function, which can be exploited via a crafted a file. archdebian
CVE-2020-35738 medium 5.5 WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" re… archsusedebian
CVE-2020-23109 medium 5.5 Buffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attackers to cause a denial of service and disclose sensitive information, via a craf… archsusedebian