CVEs from 2020
Total
4,156
critical
critical 193
high
high 470
medium
medium 675
low
low 56
% Critical
4.6%
% with KEV
3.5%
% with exploit
3.6%
Top products
- banking_digital_experience 30
- retail_xstore_point_of_service 28
- primavera_unifier 27
- retail_service_backbone 15
- financial_services_institutional_performance_analytics 10
- communications_network_charging_and_control 10
- communications_contacts_server 9
- agile_plm 8
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2020-14547 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14540 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14619 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14553 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14539 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2763 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2923 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2903 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14614 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2660 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2752 | high | — | 8.0 | 6y ago | Important: mariadb:10.3 security, bug fix, and enhancement update | |
| CVE-2020-14634 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14641 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2761 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2570 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2780 | high | — | 8.0 | 6y ago | Important: mariadb:10.3 security, bug fix, and enhancement update | |
| CVE-2020-2893 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2774 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2901 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2765 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2694 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14597 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2760 | high | — | 8.0 | 6y ago | Important: mariadb:10.3 security, bug fix, and enhancement update | |
| CVE-2020-2804 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14633 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2580 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2759 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2762 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2686 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2588 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2589 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14624 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2577 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14697 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14643 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14632 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14623 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-11538 | high | — | 8.0 | 6y ago | In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311. | |
| CVE-2020-8172 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-8174 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-11080 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-9402 | high | — | 8.0 | 6y ago | Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a sui… | |
| CVE-2020-9484 | high | — | 8.0 | 6y ago | Potential remote code execution in Apache Tomcat | |
| CVE-2020-11945 | high | — | 8.0 | 6y ago | Important: squid:4 security update | |
| CVE-2020-1967 | high | — | 8.0 | 6y ago | Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signat… | |
| CVE-2020-7039 | high | — | 8.0 | 6y ago | Important: container-tools:rhel8 security, bug fix, and enhancement update | |
| CVE-2020-1711 | high | — | 8.0 | 6y ago | Important: virt:rhel security and bug fix update | |
| CVE-2020-8608 | high | — | 8.0 | 6y ago | Important: virt:rhel security update | |
| CVE-2020-7598 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-5313 | high | — | 8.0 | 6y ago | libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow. | |
| CVE-2020-10531 | high | — | 8.0 | 6y ago | Important: nodejs:10 security update | |
| CVE-2020-8597 | high | — | 8.0 | 6y ago | Important: ppp security update | |
| CVE-2020-37247 | high | 7.8 | 7.8 | 12d ago | Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers … | |
| CVE-2020-37232 | high | 7.8 | 7.8 | 12d ago | Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Atta… | |
| CVE-2020-37231 | high | 7.8 | 7.8 | 12d ago | Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Atta… | |
| CVE-2020-37230 | high | 7.8 | 7.8 | 12d ago | Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path… | |
| CVE-2020-37229 | high | 7.8 | 7.8 | 12d ago | OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unqu… | |
| CVE-2020-37223 | high | 7.8 | 7.8 | 15d ago | IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a maliciou… | |
| CVE-2020-10648 | high | 7.8 | 7.8 | 6y ago | Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default con… | |
| CVE-2020-37245 | high | 7.5 | 7.5 | 12d ago | Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequ… | |
| CVE-2020-37220 | high | 7.5 | 7.5 | 15d ago | Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can quer… | |
| CVE-2020-37219 | high | 7.5 | 7.5 | 15d ago | Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET reques… | |
| CVE-2020-37130 | high | 7.5 | 7.5 | 4mo ago | Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 byte… | |
| CVE-2020-37015 | high | 7.5 | 7.5 | 4mo ago | The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file p… | |
| CVE-2020-37011 | high | 7.5 | 7.5 | 4mo ago | Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially cr… | |
| CVE-2020-25720 | high | 7.5 | 7.5 | 2y ago | A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-se… | |
| CVE-2020-37222 | high | 7.2 | 7.2 | 15d ago | Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs reply endpoi… | |
| CVE-2020-37226 | high | 7.1 | 7.1 | 15d ago | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att… | |
| CVE-2020-37224 | high | 7.1 | 7.1 | 15d ago | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att… | |
| CVE-2020-17103 | high | 7.0 | 7.0 | 6y ago | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
| CVE-2020-13965 | unknown | — | 1.5 | 2y ago | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. | |
| CVE-2020-12641 | unknown | — | 1.5 | 3y ago | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. | |
| CVE-2020-7961 | unknown | — | 1.5 | 4y ago | Deserialization of Untrusted Data in Liferay Portal | |
| CVE-2020-17530 | unknown | — | 1.5 | 4y ago | Remote code execution in Apache Struts | |
| CVE-2020-0041 | unknown | — | 1.5 | 5y ago | In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges n… | |
| CVE-2020-17519 | unknown | — | 1.5 | 6y ago | Path Traversal in Apache Flink | |
| CVE-2020-1956 | unknown | — | 1.5 | 6y ago | Command Injection in Kylin | |
| CVE-2020-5410 | unknown | — | 1.5 | 6y ago | Directory traversal attack in Spring Cloud Config | |
| CVE-2020-10199 | unknown | — | 1.5 | 6y ago | Nexus Repository Manager 3 - Remote Code Execution | |
| CVE-2020-0009 | unknown | — | 1.0 | — | In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalation of privilege by corrupting memory shared betwee… | |
| CVE-2020-0433 | unknown | — | — | — | In blk_mq_queue_tag_busy_iter of blk-mq-tag.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges nee… | |
| CVE-2020-10742 | unknown | — | — | — | A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmallo… | |
| CVE-2020-10769 | unknown | — | — | — | A buffer over-read flaw was found in RH kernel versions before 5.0 in crypto_authenc_extractkeys in crypto/authenc.c in the IPsec Cryptographic algorithm's module, authenc. When a payload longer than… | |
| CVE-2020-29569 | unknown | — | — | — | An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thread handler to reset ring->xenblkd to NULL when st… | |
| CVE-2020-36387 | unknown | — | — | — | An issue was discovered in the Linux kernel before 5.8.2. fs/io_uring.c has a use-after-free related to io_async_task_func and ctx reference holding, aka CID-6d816e088c35. | |
| CVE-2020-22402 | unknown | — | — | — | Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reads an email containing malicious code. | |
| CVE-2020-14416 | unknown | — | — | — | In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka CID-0ace17d56824. This affects drivers/net/sli… | |
| CVE-2020-25211 | unknown | — | — | — | In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctn… | |
| CVE-2020-18670 | unknown | — | — | — | Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php. | |
| CVE-2020-25671 | unknown | — | — | — | A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations. | |
| CVE-2020-35513 | unknown | — | — | — | A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if b… | |
| CVE-2020-16145 | unknown | — | — | — | Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15. | |
| CVE-2020-10690 | unknown | — | — | — | There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp… | |
| CVE-2020-25673 | unknown | — | — | — | A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system. | |
| CVE-2020-36779 | unknown | — | — | — | In the Linux kernel, the following vulnerability has been resolved: i2c: stm32f7: fix reference leak when pm_runtime_get_sync fails The PM reference count is not expected to be incremented on retur… | |
| CVE-2020-0465 | unknown | — | — | — | In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges… | |
| CVE-2020-27194 | unknown | — | — | — | An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values, aka CID-5b9fbeb75b6a. | |
| CVE-2020-0110 | unknown | — | — | — | In psi_write of psi.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User int… | |
| CVE-2020-0432 | unknown | — | — | — | In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. U… | |
| CVE-2020-11494 | unknown | — | — | — | An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive infor… |