CVEs from 2020

3,795 normalized CVEs published or assigned in this year.

Total
3,795
critical
critical 206
high
high 563
medium
medium 745
low
low 59
% Critical
5.4%
% with KEV
3.8%
% with exploit
5.4%

Top products

  • retail_xstore_point_of_service 33
  • banking_digital_experience 30
  • primavera_unifier 29
  • retail_service_backbone 15
  • financial_services_institutional_performance_analytics 13
  • insurance_policy_administration_j2ee 11
  • communications_network_charging_and_control 10
  • enterprise_manager_base_platform 10
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-14392 unknown An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's avai…
CVE-2020-15959 unknown Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from pro…
CVE-2020-14004 unknown An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an u…
CVE-2020-29663 unknown Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.…
CVE-2020-15562 unknown An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in th…
CVE-2020-13964 unknown An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.
CVE-2020-12626 unknown An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.
CVE-2020-12625 unknown An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
CVE-2020-12640 unknown Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
CVE-2020-10701 unknown A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for th…
CVE-2020-12430 unknown An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is respons…
CVE-2020-15708 unknown Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.
CVE-2020-6503 unknown Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2020-6532 unknown Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6542 unknown Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6567 unknown Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML pa…
CVE-2020-14398 unknown An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.
CVE-2020-14400 unknown An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerabil…
CVE-2020-36023 unknown An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function.
CVE-2020-21890 unknown Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via openi…
CVE-2020-11934 unknown It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the system xdg-open. OpenURL() in usersession/userd/launcher.go would alter $XDG_DATA_DI…
CVE-2020-27352 unknown When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and …
CVE-2020-24361 unknown SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.
CVE-2020-25887 unknown Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file.
CVE-2020-21583 unknown An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.
CVE-2020-25623 unknown Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.
CVE-2020-29569 unknown An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thread handler to reset ring->xenblkd to NULL when st…
CVE-2020-6543 unknown Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6538 unknown Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2020-6558 unknown Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVE-2020-6546 unknown Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
CVE-2020-6547 unknown Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.
CVE-2020-6550 unknown Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6555 unknown Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2020-6560 unknown Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2020-6556 unknown Heap buffer overflow in SwiftShader in Google Chrome prior to 84.0.4147.135 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6559 unknown Use after free in presentation API in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6492 unknown Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2020-6501 unknown Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2020-13753 unknown The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-des…
CVE-2020-9947 unknown A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS 14.0, Saf…
CVE-2020-19860 unknown When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zon…
CVE-2020-36843 unknown 1y ago Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check
CVE-2020-27534 unknown 2y ago util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.T…
CVE-2020-15136 unknown 2y ago In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on e…
CVE-2020-15114 unknown 2y ago In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoin…
CVE-2020-15113 unknown 2y ago In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS con…
CVE-2020-24922 unknown 3y ago xuxueli xxl-job Cross-Site Request Forgery Vulnerability
CVE-2020-21485 unknown 3y ago Alluxio Cross Site Scripting vulnerability
CVE-2020-22755 unknown 3y ago MCMS vulnerable to arbitrary code execution via crafted thumbnail
CVE-2020-20913 unknown 3y ago Ming-Soft MCMS vulnerable to SQL injection
CVE-2020-36640 unknown 4y ago bonita-connector-webservice XML External Entity vulnerability
CVE-2020-36641 unknown 4y ago aXMLRPC XML External Entity vulnerability
CVE-2020-15115 unknown 4y ago etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess …
CVE-2020-15106 unknown 4y ago In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a WAL file and no additional validation is done on …
CVE-2020-15112 unknown 4y ago In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are b…
CVE-2020-23622 unknown 4y ago 4thline cling uPnP protocol issue can lead to denial of service
CVE-2020-7677 unknown 4y ago thenify before 3.3.1 made use of unsafe calls to `eval`.
CVE-2020-28191 unknown 4y ago Togglz console missing cross-site request forgery (CSRF) protection
CVE-2020-10650 unknown 4y ago A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta…
CVE-2020-28865 unknown 4y ago Insufficiently Protected Credentials in PowerJob
CVE-2020-28088 unknown 4y ago Jeecg-Boot CMS arbitrary file upload vulnerability
CVE-2020-7021 unknown 4y ago Insertion of Sensitive Information into Log File in Elasticsearch
CVE-2020-29582 unknown 4y ago Incorrect Default Permissions in JetBrains Kotlin
CVE-2020-25476 unknown 4y ago Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via User Name Parameter
CVE-2020-8920 unknown 4y ago Information leak in Gerrit
CVE-2020-16971 unknown 4y ago Azure SDK for Java Security Feature Bypass Vulnerability
CVE-2020-27822 unknown 4y ago Wildfly has a memory leak vulnerability
CVE-2020-2323 unknown 4y ago Missing permission checks in Jenkins Chaos Monkey Plugin
CVE-2020-2320 unknown 4y ago Jenkins Plugin Installation Manager Tool did not verify plugin downloads
CVE-2020-2324 unknown 4y ago XXE vulnerability in Jenkins CVS Plugin
CVE-2020-2322 unknown 4y ago Missing permission checks in Jenkins Chaos Monkey Plugin
CVE-2020-2321 unknown 4y ago CSRF vulnerability in Jenkins Shelve Project Plugin
CVE-2020-2319 unknown 4y ago Password stored in plain text by Jenkins VMware Lab Manager Slaves Plugin
CVE-2020-2318 unknown 4y ago Passwords stored in plain text by Mail Commander Plugin for Jenkins-ci Plugin
CVE-2020-2312 unknown 4y ago Password written to the build log by Jenkins SQLPlus Script Runner Plugin
CVE-2020-2308 unknown 4y ago Missing Authorization in Jenkins Kubernetes Plugin
CVE-2020-2313 unknown 4y ago Missing permission checks in Jenkins Azure Key Vault Plugin allow enumerating credentials IDs
CVE-2020-2311 unknown 4y ago Missing permission check in Jenkins AWS Global Configuration Plugin allows replacing plugin configuration
CVE-2020-2316 unknown 4y ago Stored XSS vulnerability in Jenkins Static Analysis Utilities Plugin
CVE-2020-2315 unknown 4y ago XXE vulnerability in Jenkins Visualworks Store Plugin
CVE-2020-2310 unknown 4y ago Missing permission checks in Jenkins Ansible Plugin allow enumerating credentials IDs
CVE-2020-2309 unknown 4y ago Missing authorization in Jenkins Kubernetes Plugin
CVE-2020-2314 unknown 4y ago Password stored in plain text by Jenkins AppSpider Plugin
CVE-2020-2303 unknown 4y ago CSRF vulnerability in Jenkins Active Directory Plugin
CVE-2020-2302 unknown 4y ago Missing permission check in Jenkins Active Directory Plugin allows accessing domain health check page
CVE-2020-2299 unknown 4y ago Improper Authentication in Jenkins Active Directory Plugin
CVE-2020-2304 unknown 4y ago XXE vulnerability in Jenkins Subversion Plugin
CVE-2020-2307 unknown 4y ago Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin
CVE-2020-2306 unknown 4y ago Missing Authorization in Jenkins Mercurial Plugin
CVE-2020-2300 unknown 4y ago Improper Authentication (empty password) in Jenkins Active Directory Plugin
CVE-2020-2301 unknown 4y ago Authentication cache in Active Directory Jenkins Plugin allows logging in with any password
CVE-2020-2305 unknown 4y ago XXE vulnerability in Jenkins Mercurial Plugin
CVE-2020-25689 unknown 4y ago Uncontrolled Resource Consumption in WildFly
CVE-2020-10721 unknown 4y ago fabric8-maven-plugin: insecure way to construct Yaml Object leading to remote code execution
CVE-2020-2294 unknown 4y ago Missing permission checks in Jenkins Maven Cascade Release Plugin
CVE-2020-2295 unknown 4y ago CSRF vulnerability in Jenkins Maven Cascade Release Plugin
CVE-2020-2298 unknown 4y ago XXE vulnerability in Jenkins Nerrvana Plugin
CVE-2020-2297 unknown 4y ago Access token stored in plain text by Jenkins SMS Notification Plugin
CVE-2020-2290 unknown 4y ago Stored XSS vulnerability in Jenkins Active Choices Plugin