CVEs from 2020
Total
4,156
critical
critical 193
high
high 470
medium
medium 674
low
low 57
% Critical
4.6%
% with KEV
3.5%
% with exploit
3.6%
Top products
- banking_digital_experience 30
- retail_xstore_point_of_service 28
- primavera_unifier 27
- retail_service_backbone 15
- financial_services_institutional_performance_analytics 10
- communications_network_charging_and_control 10
- communications_contacts_server 9
- agile_plm 8
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2020-2686 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2588 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2923 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2589 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2928 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2577 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14697 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2921 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14643 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14632 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14623 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2904 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2897 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2853 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2903 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14550 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2660 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2752 | high | — | 8.0 | 6y ago | Important: mariadb:10.3 security, bug fix, and enhancement update | |
| CVE-2020-2926 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14597 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14553 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14619 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14620 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14656 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14651 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14631 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14702 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14725 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2770 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2779 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2892 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2895 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2896 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2898 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2924 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2925 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2760 | high | — | 8.0 | 6y ago | Important: mariadb:10.3 security, bug fix, and enhancement update | |
| CVE-2020-11538 | high | — | 8.0 | 6y ago | In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311. | |
| CVE-2020-8172 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-8174 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-11080 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-9402 | high | — | 8.0 | 6y ago | Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a sui… | |
| CVE-2020-9484 | high | — | 8.0 | 6y ago | Potential remote code execution in Apache Tomcat | |
| CVE-2020-11945 | high | — | 8.0 | 6y ago | Important: squid:4 security update | |
| CVE-2020-1967 | high | — | 8.0 | 6y ago | Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signat… | |
| CVE-2020-7039 | high | — | 8.0 | 6y ago | Important: container-tools:rhel8 security, bug fix, and enhancement update | |
| CVE-2020-1711 | high | — | 8.0 | 6y ago | Important: virt:rhel security and bug fix update | |
| CVE-2020-8608 | high | — | 8.0 | 6y ago | Important: virt:rhel security update | |
| CVE-2020-7598 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-5313 | high | — | 8.0 | 6y ago | libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow. | |
| CVE-2020-10531 | high | — | 8.0 | 6y ago | Important: nodejs:10 security update | |
| CVE-2020-8597 | high | — | 8.0 | 6y ago | Important: ppp security update | |
| CVE-2020-37247 | high | 7.8 | 7.8 | 12d ago | Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers … | |
| CVE-2020-37232 | high | 7.8 | 7.8 | 12d ago | Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Atta… | |
| CVE-2020-37231 | high | 7.8 | 7.8 | 12d ago | Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Atta… | |
| CVE-2020-37230 | high | 7.8 | 7.8 | 12d ago | Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path… | |
| CVE-2020-37229 | high | 7.8 | 7.8 | 12d ago | OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unqu… | |
| CVE-2020-37223 | high | 7.8 | 7.8 | 15d ago | IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a maliciou… | |
| CVE-2020-10648 | high | 7.8 | 7.8 | 6y ago | Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default con… | |
| CVE-2020-37245 | high | 7.5 | 7.5 | 12d ago | Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequ… | |
| CVE-2020-37220 | high | 7.5 | 7.5 | 15d ago | Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can quer… | |
| CVE-2020-37219 | high | 7.5 | 7.5 | 15d ago | Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET reques… | |
| CVE-2020-37130 | high | 7.5 | 7.5 | 4mo ago | Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 byte… | |
| CVE-2020-37015 | high | 7.5 | 7.5 | 4mo ago | The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file p… | |
| CVE-2020-37011 | high | 7.5 | 7.5 | 4mo ago | Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially cr… | |
| CVE-2020-25720 | high | 7.5 | 7.5 | 2y ago | A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-se… | |
| CVE-2020-37222 | high | 7.2 | 7.2 | 15d ago | Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs reply endpoi… | |
| CVE-2020-37226 | high | 7.1 | 7.1 | 15d ago | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att… | |
| CVE-2020-37224 | high | 7.1 | 7.1 | 15d ago | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att… | |
| CVE-2020-1472 | medium | — | 7.0 | 5y ago | Moderate: samba security, bug fix, and enhancement update | |
| CVE-2020-36193 | medium | — | 7.0 | 5y ago | Moderate: php:7.4 security update | |
| CVE-2020-17103 | high | 7.0 | 7.0 | 6y ago | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
| CVE-2020-28949 | medium | — | 7.0 | 6y ago | Moderate: php:7.4 security update | |
| CVE-2020-1938 | medium | — | 7.0 | 6y ago | Improper Privilege Management in Tomcat | |
| CVE-2020-11023 | medium | — | 7.0 | 6y ago | Moderate: gcc security update | |
| CVE-2020-37240 | medium | 6.4 | 6.4 | 12d ago | Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can ins… | |
| CVE-2020-37238 | medium | 6.4 | 6.4 | 12d ago | CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers… | |
| CVE-2020-37237 | medium | 6.4 | 6.4 | 12d ago | Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers wi… | |
| CVE-2020-37236 | medium | 6.4 | 6.4 | 12d ago | NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news additio… | |
| CVE-2020-37235 | medium | 6.4 | 6.4 | 12d ago | WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parame… | |
| CVE-2020-37233 | medium | 6.4 | 6.4 | 12d ago | WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the fi… | |
| CVE-2020-37225 | medium | 6.4 | 6.4 | 15d ago | Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in… | |
| CVE-2020-37246 | medium | 6.2 | 6.2 | 12d ago | Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers ca… | |
| CVE-2020-37234 | medium | 6.2 | 6.2 | 12d ago | Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can … | |
| CVE-2020-26409 | medium | — | 5.5 | — | multiple issues in gitlab | |
| CVE-2020-10878 | medium | — | 5.5 | — | Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of in… | |
| CVE-2020-29573 | medium | — | 5.5 | — | sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long … | |
| CVE-2020-26421 | medium | — | 5.5 | — | Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. | |
| CVE-2020-36405 | medium | — | 5.5 | — | arbitrary code execution in keystone | |
| CVE-2020-36221 | medium | — | 5.5 | — | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssu… | |
| CVE-2020-15358 | medium | — | 5.5 | — | In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation. | |
| CVE-2020-36222 | medium | — | 5.5 | — | A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service. | |
| CVE-2020-10595 | medium | — | 5.5 | — | pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library. It may overflow a buffer provided by the underly… | |
| CVE-2020-6851 | medium | — | 5.5 | — | OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation. | |
| CVE-2020-24491 | medium | — | 5.5 | — | information disclosure in intel-ucode | |
| CVE-2020-15078 | medium | — | 5.5 | — | OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentia… | |
| CVE-2020-11810 | medium | — | 5.5 | — | An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arri… | |
| CVE-2020-35498 | medium | — | 5.5 | — | A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow i… | |
| CVE-2020-21597 | medium | — | 5.5 | — | libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file. | |
| CVE-2020-16154 | medium | — | 5.5 | — | The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass. |