CVEs from 2020
Total
4,156
critical
critical 193
high
high 470
medium
medium 674
low
low 57
% Critical
4.6%
% with KEV
3.5%
% with exploit
3.6%
Top products
- banking_digital_experience 30
- retail_xstore_point_of_service 28
- primavera_unifier 27
- retail_service_backbone 15
- financial_services_institutional_performance_analytics 10
- communications_network_charging_and_control 10
- communications_contacts_server 9
- agile_plm 8
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2020-2930 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14663 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2780 | high | — | 8.0 | 6y ago | Important: mariadb:10.3 security, bug fix, and enhancement update | |
| CVE-2020-2763 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14620 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14576 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14568 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14567 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14559 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14547 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14540 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14539 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2921 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14702 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14631 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14651 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14656 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2686 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2897 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2901 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2765 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2853 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2574 | high | — | 8.0 | 6y ago | Important: mariadb:10.3 security, bug fix, and enhancement update | |
| CVE-2020-2584 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2904 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2579 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2761 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14725 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14641 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14550 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14633 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-14597 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2923 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2577 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2589 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2928 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-2774 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |
| CVE-2020-11538 | high | — | 8.0 | 6y ago | In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311. | |
| CVE-2020-8172 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-8174 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-11080 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-9402 | high | — | 8.0 | 6y ago | Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a sui… | |
| CVE-2020-9484 | high | — | 8.0 | 6y ago | Potential remote code execution in Apache Tomcat | |
| CVE-2020-11945 | high | — | 8.0 | 6y ago | Important: squid:4 security update | |
| CVE-2020-1967 | high | — | 8.0 | 6y ago | Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signat… | |
| CVE-2020-7039 | high | — | 8.0 | 6y ago | Important: container-tools:rhel8 security, bug fix, and enhancement update | |
| CVE-2020-1711 | high | — | 8.0 | 6y ago | Important: virt:rhel security and bug fix update | |
| CVE-2020-8608 | high | — | 8.0 | 6y ago | Important: virt:rhel security update | |
| CVE-2020-7598 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |
| CVE-2020-5313 | high | — | 8.0 | 6y ago | libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow. | |
| CVE-2020-10531 | high | — | 8.0 | 6y ago | Important: nodejs:10 security update | |
| CVE-2020-8597 | high | — | 8.0 | 6y ago | Important: ppp security update | |
| CVE-2020-37247 | high | 7.8 | 7.8 | 12d ago | Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers … | |
| CVE-2020-37232 | high | 7.8 | 7.8 | 12d ago | Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Atta… | |
| CVE-2020-37231 | high | 7.8 | 7.8 | 12d ago | Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Atta… | |
| CVE-2020-37230 | high | 7.8 | 7.8 | 12d ago | Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path… | |
| CVE-2020-37229 | high | 7.8 | 7.8 | 12d ago | OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unqu… | |
| CVE-2020-37223 | high | 7.8 | 7.8 | 15d ago | IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a maliciou… | |
| CVE-2020-10648 | high | 7.8 | 7.8 | 6y ago | Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default con… | |
| CVE-2020-37245 | high | 7.5 | 7.5 | 12d ago | Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequ… | |
| CVE-2020-37220 | high | 7.5 | 7.5 | 15d ago | Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can quer… | |
| CVE-2020-37219 | high | 7.5 | 7.5 | 15d ago | Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET reques… | |
| CVE-2020-37130 | high | 7.5 | 7.5 | 4mo ago | Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 byte… | |
| CVE-2020-37015 | high | 7.5 | 7.5 | 4mo ago | The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file p… | |
| CVE-2020-37011 | high | 7.5 | 7.5 | 4mo ago | Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially cr… | |
| CVE-2020-25720 | high | 7.5 | 7.5 | 2y ago | A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-se… | |
| CVE-2020-37222 | high | 7.2 | 7.2 | 15d ago | Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs reply endpoi… | |
| CVE-2020-37226 | high | 7.1 | 7.1 | 15d ago | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att… | |
| CVE-2020-37224 | high | 7.1 | 7.1 | 15d ago | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att… | |
| CVE-2020-1472 | medium | — | 7.0 | 5y ago | Moderate: samba security, bug fix, and enhancement update | |
| CVE-2020-36193 | medium | — | 7.0 | 5y ago | Moderate: php:7.4 security update | |
| CVE-2020-17103 | high | 7.0 | 7.0 | 6y ago | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
| CVE-2020-28949 | medium | — | 7.0 | 6y ago | Moderate: php:7.4 security update | |
| CVE-2020-1938 | medium | — | 7.0 | 6y ago | Improper Privilege Management in Tomcat | |
| CVE-2020-11023 | medium | — | 7.0 | 6y ago | Moderate: gcc security update | |
| CVE-2020-37240 | medium | 6.4 | 6.4 | 12d ago | Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can ins… | |
| CVE-2020-37238 | medium | 6.4 | 6.4 | 12d ago | CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers… | |
| CVE-2020-37237 | medium | 6.4 | 6.4 | 12d ago | Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers wi… | |
| CVE-2020-37236 | medium | 6.4 | 6.4 | 12d ago | NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news additio… | |
| CVE-2020-37235 | medium | 6.4 | 6.4 | 12d ago | WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parame… | |
| CVE-2020-37233 | medium | 6.4 | 6.4 | 12d ago | WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the fi… | |
| CVE-2020-37225 | medium | 6.4 | 6.4 | 15d ago | Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in… | |
| CVE-2020-37246 | medium | 6.2 | 6.2 | 12d ago | Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers ca… | |
| CVE-2020-37234 | medium | 6.2 | 6.2 | 12d ago | Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can … | |
| CVE-2020-28196 | medium | — | 5.5 | — | MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite l… | |
| CVE-2020-12244 | medium | — | 5.5 | — | An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allow… | |
| CVE-2020-35850 | medium | — | 5.5 | — | multiple issues in cockpit | |
| CVE-2020-26413 | medium | — | 5.5 | — | multiple issues in gitlab | |
| CVE-2020-26412 | medium | — | 5.5 | — | information disclosure in gitlab | |
| CVE-2020-29510 | medium | — | 5.5 | — | The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave … | |
| CVE-2020-1730 | medium | — | 5.5 | — | A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been f… | |
| CVE-2020-12402 | medium | — | 5.5 | — | During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perfo… | |
| CVE-2020-27840 | medium | — | 5.5 | — | A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds me… | |
| CVE-2020-36229 | medium | — | 5.5 | — | A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service. | |
| CVE-2020-27844 | medium | — | 5.5 | — | A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bou… | |
| CVE-2020-8284 | medium | — | 5.5 | — | Moderate: curl security and bug fix update | |
| CVE-2020-10543 | medium | — | 5.5 | — | Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow. | |
| CVE-2020-26117 | medium | — | 5.5 | — | In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a cert… | |
| CVE-2020-36221 | medium | — | 5.5 | — | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssu… | |
| CVE-2020-36226 | medium | — | 5.5 | — | A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service. |