CVEs from 2020
Total
4,160
critical
critical 193
high
high 470
medium
medium 675
low
low 56
% Critical
4.6%
% with KEV
3.5%
% with exploit
3.6%
Top products
- banking_digital_experience 30
- retail_xstore_point_of_service 28
- primavera_unifier 27
- retail_service_backbone 15
- financial_services_institutional_performance_analytics 10
- communications_network_charging_and_control 10
- communications_contacts_server 9
- agile_plm 8
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2020-14547 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14540 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14641 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14619 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14553 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14634 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14539 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2903 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2780 | high | — | 8.0 | 6y ago | Important: mariadb:10.3 security, bug fix, and enhancement update | |
| CVE-2020-2930 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2926 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2763 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14614 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2761 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14624 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2760 | high | — | 8.0 | 6y ago | Important: mariadb:10.3 security, bug fix, and enhancement update | |
| CVE-2020-2660 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2580 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2893 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2774 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2694 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14597 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2901 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2765 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14633 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2804 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2759 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2762 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2686 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2588 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2589 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2577 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14697 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14643 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14632 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14623 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2570 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-11538 | high | — | 8.0 | 6y ago | In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311. | |
| CVE-2020-8172 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-8174 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-11080 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-9402 | high | — | 8.0 | 6y ago | Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a sui… | |
| CVE-2020-9484 | high | — | 8.0 | 6y ago | Potential remote code execution in Apache Tomcat | |
| CVE-2020-11945 | high | — | 8.0 | 6y ago | Important: squid:4 security update | |
| CVE-2020-1967 | high | — | 8.0 | 6y ago | Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signat… | |
| CVE-2020-7039 | high | — | 8.0 | 6y ago | Important: container-tools:rhel8 security, bug fix, and enhancement update | |
| CVE-2020-1711 | high | — | 8.0 | 6y ago | Important: virt:rhel security and bug fix update | |
| CVE-2020-8608 | high | — | 8.0 | 6y ago | Important: virt:rhel security update | |
| CVE-2020-7598 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-5313 | high | — | 8.0 | 6y ago | libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow. | |
| CVE-2020-10531 | high | — | 8.0 | 6y ago | Important: nodejs:10 security update | |
| CVE-2020-8597 | high | — | 8.0 | 6y ago | Important: ppp security update | |
| CVE-2020-37247 | high | 7.8 | 7.8 | 12d ago | Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers … | |
| CVE-2020-37232 | high | 7.8 | 7.8 | 12d ago | Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Atta… | |
| CVE-2020-37231 | high | 7.8 | 7.8 | 12d ago | Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Atta… | |
| CVE-2020-37230 | high | 7.8 | 7.8 | 12d ago | Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path… | |
| CVE-2020-37229 | high | 7.8 | 7.8 | 12d ago | OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unqu… | |
| CVE-2020-37223 | high | 7.8 | 7.8 | 15d ago | IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a maliciou… | |
| CVE-2020-10648 | high | 7.8 | 7.8 | 6y ago | Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default con… | |
| CVE-2020-37245 | high | 7.5 | 7.5 | 12d ago | Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequ… | |
| CVE-2020-37220 | high | 7.5 | 7.5 | 15d ago | Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can quer… | |
| CVE-2020-37219 | high | 7.5 | 7.5 | 15d ago | Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET reques… | |
| CVE-2020-37130 | high | 7.5 | 7.5 | 4mo ago | Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 byte… | |
| CVE-2020-37015 | high | 7.5 | 7.5 | 4mo ago | The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file p… | |
| CVE-2020-37011 | high | 7.5 | 7.5 | 4mo ago | Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially cr… | |
| CVE-2020-25720 | high | 7.5 | 7.5 | 2y ago | A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-se… | |
| CVE-2020-37222 | high | 7.2 | 7.2 | 15d ago | Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs reply endpoi… | |
| CVE-2020-37226 | high | 7.1 | 7.1 | 15d ago | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att… | |
| CVE-2020-37224 | high | 7.1 | 7.1 | 15d ago | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att… | |
| CVE-2020-17103 | high | 7.0 | 7.0 | 6y ago | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
| CVE-2020-13965 | unknown | — | 1.5 | 2y ago | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. | |
| CVE-2020-12641 | unknown | — | 1.5 | 3y ago | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. | |
| CVE-2020-7961 | unknown | — | 1.5 | 4y ago | Deserialization of Untrusted Data in Liferay Portal | |
| CVE-2020-17530 | unknown | — | 1.5 | 4y ago | Remote code execution in Apache Struts | |
| CVE-2020-0041 | unknown | — | 1.5 | 5y ago | In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges n… | |
| CVE-2020-17519 | unknown | — | 1.5 | 6y ago | Path Traversal in Apache Flink | |
| CVE-2020-1956 | unknown | — | 1.5 | 6y ago | Command Injection in Kylin | |
| CVE-2020-5410 | unknown | — | 1.5 | 6y ago | Directory traversal attack in Spring Cloud Config | |
| CVE-2020-10199 | unknown | — | 1.5 | 6y ago | Nexus Repository Manager 3 - Remote Code Execution | |
| CVE-2020-0009 | unknown | — | 1.0 | — | In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalation of privilege by corrupting memory shared betwee… | |
| CVE-2020-36775 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential deadlock Using f2fs_trylock_op() in f2fs_write_compressed_pages() to avoid potential deadlock like w… | |
| CVE-2020-8428 | unknown | — | — | — | fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel … | |
| CVE-2020-29534 | unknown | — | — | — | An issue was discovered in the Linux kernel before 5.9.3. io_uring takes a non-refcounted reference to the files_struct of the process that submitted a request, causing execve() to incorrectly optimi… | |
| CVE-2020-36766 | unknown | — | — | — | An issue was discovered in the Linux kernel before 5.8.6. drivers/media/cec/core/cec-api.c leaks one byte of kernel memory on specific hardware to unprivileged users, because of directly assigning lo… | |
| CVE-2020-0433 | unknown | — | — | — | In blk_mq_queue_tag_busy_iter of blk-mq-tag.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges nee… | |
| CVE-2020-11884 | unknown | — | — | — | In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails… | |
| CVE-2020-22402 | unknown | — | — | — | Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reads an email containing malicious code. | |
| CVE-2020-36311 | unknown | — | — | — | An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of service (soft lockup) by triggering destruction of a large SEV VM (which requires … | |
| CVE-2020-0429 | unknown | — | — | — | In l2tp_session_delete and related functions of l2tp_core.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privil… | |
| CVE-2020-14390 | unknown | — | — | — | A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-of-bounds memory write can occur leading to memory corruption or a denial of service. Due to the nat… | |
| CVE-2020-18670 | unknown | — | — | — | Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php. | |
| CVE-2020-14416 | unknown | — | — | — | In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka CID-0ace17d56824. This affects drivers/net/sli… | |
| CVE-2020-25668 | unknown | — | — | — | A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op. | |
| CVE-2020-16145 | unknown | — | — | — | Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15. | |
| CVE-2020-25670 | unknown | — | — | — | A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations. | |
| CVE-2020-29370 | unknown | — | — | — | An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71. | |
| CVE-2020-36313 | unknown | — | — | — | An issue was discovered in the Linux kernel before 5.7. The KVM subsystem allows out-of-range access to memslots after a deletion, aka CID-0774a964ef56. This affects arch/s390/kvm/kvm-s390.c, include… | |
| CVE-2020-36776 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/cpufreq_cooling: Fix slab OOB issue Slab OOB issue is scanned by KASAN in cpu_power_to_freq(). If power is limite… | |
| CVE-2020-29568 | unknown | — | — | — | An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is a… | |
| CVE-2020-14331 | unknown | — | — | — | A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of… |