CVEs from 2020

3,802 normalized CVEs published or assigned in this year.

Total
3,802
critical
critical 206
high
high 563
medium
medium 743
low
low 59
% Critical
5.4%
% with KEV
3.8%
% with exploit
5.4%

Top products

  • retail_xstore_point_of_service 33
  • banking_digital_experience 30
  • primavera_unifier 29
  • retail_service_backbone 15
  • financial_services_institutional_performance_analytics 13
  • insurance_policy_administration_j2ee 11
  • communications_network_charging_and_control 10
  • enterprise_manager_base_platform 10
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-35634 medium 5.5 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_sface() s…
CVE-2020-35633 medium 5.5 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_sface() s…
CVE-2020-35631 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-18771 medium 5.5 Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
CVE-2020-25669 medium 5.5 A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd being freed. Though the dangling pointer is set to NULL in sunkb…
CVE-2020-28635 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-24119 medium 5.5 A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
CVE-2020-25693 medium 5.5 A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be triggered by a specially crafted input file processed by CImg, which can l…
CVE-2020-35132 medium 5.5 An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
CVE-2020-28634 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-28601 medium 5.5 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of…
CVE-2020-35499 medium 5.5 A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have a sanity check for a socket connection, when usin…
CVE-2020-28605 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-28633 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-35964 medium 5.5 track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing.
CVE-2020-28636 medium 5.5 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->…
CVE-2020-23928 medium 5.5 An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_code_adobe.c has a heap-based buffer over-read.
CVE-2020-21600 medium 5.5 libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file.
CVE-2020-21602 medium 5.5 libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_bipred_16_fallback function, which can be exploited via a crafted a file.
CVE-2020-21604 medium 5.5 libde265 v1.0.4 contains a heap buffer overflow fault in the _mm_loadl_epi64 function, which can be exploited via a crafted a file.
CVE-2020-21594 medium 5.5 libde265 v1.0.4 contains a heap buffer overflow in the put_epel_hv_fallback function, which can be exploited via a crafted a file.
CVE-2020-21596 medium 5.5 libde265 v1.0.4 contains a global buffer overflow in the decode_CABAC_bit function, which can be exploited via a crafted a file.
CVE-2020-23932 medium 5.5 An issue was discovered in gpac before 1.0.1. A NULL pointer dereference exists in the function dump_isom_sdp located in filedump.c. It allows an attacker to cause Denial of Service.
CVE-2020-36151 medium 5.5 Incorrect handling of input data in mysofa_resampler_reset_mem function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and overwriting large memory block.
CVE-2020-7957 medium 5.5 The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a den…
CVE-2020-28599 medium 5.5 A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code execution. An attack…
CVE-2020-26664 medium 5.5 arbitrary code execution in vlc
CVE-2020-37174 medium 5.5 5.5 23d ago WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering XSS payloads in design …
CVE-2020-37169 medium 5.5 5.5 23d ago WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-u…
CVE-2020-36855 medium 5.5 5.5 8mo ago A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the component dcmqrscp. The manipulation of the argument StorageQuota leads to stac…
CVE-2020-16156 medium 5.5 1y ago RHSA-2025:8432: perl-CPAN security update (Moderate)
CVE-2020-13790 medium 5.5 1y ago RHSA-2025:7540: libjpeg-turbo security update (Moderate)
CVE-2020-27792 medium 5.5 1y ago RHSA-2025:4362: ghostscript security update (Moderate)
CVE-2020-27827 medium 5.5 2y ago Moderate: lldpd security update
CVE-2020-10135 medium 5.5 2y ago RHSA-2024:9315: kernel security update (Moderate)
CVE-2020-26154 medium 5.5 2y ago RHEA-2024:8852: libproxy bug fix and enhancement update (Moderate)
CVE-2020-25219 medium 5.5 2y ago RHEA-2024:8852: libproxy bug fix and enhancement update (Moderate)
CVE-2020-36777 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: Fix memory leak in dvb_media_device_free() dvb_media_device_free() is leaking memory. Free `dvbdev->adapter->conn`…
CVE-2020-18652 medium 5.5 2y ago RHSA-2024:3066: exempi security update (Moderate)
CVE-2020-18651 medium 5.5 2y ago RHSA-2024:3066: exempi security update (Moderate)
CVE-2020-15778 medium 5.5 2y ago scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that t…
CVE-2020-25656 medium 5.5 2y ago A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access …
CVE-2020-36024 medium 5.5 2y ago An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.
CVE-2020-18770 medium 5.5 2y ago Moderate: zziplib security update
CVE-2020-14370 medium 5.5 2y ago RHSA-2021:0531: container-tools:rhel8 security, bug fix, and enhancement update (Moderate)
CVE-2020-28991 medium 5.5 2y ago Improper Access Control in Gitea
CVE-2020-28241 medium 5.5 2y ago RHSA-2024:0768: libmaxminddb security update (Moderate)
CVE-2020-35177 medium 5.5 2y ago Enumeration of users in HashiCorp Vault in github.com/hashicorp/vault
CVE-2020-28053 medium 5.5 2y ago Privilege Escalation in HashiCorp Consul in github.com/hashicorp/consul
CVE-2020-25201 medium 5.5 2y ago Denial of service in HashiCorp Consul in github.com/hashicorp/consul
CVE-2020-22217 medium 5.5 3y ago RHSA-2023:7207: c-ares security update (Moderate)
CVE-2020-12762 medium 5.5 3y ago RHSA-2023:6976: libfastjson security update (Moderate)
CVE-2020-24736 medium 5.5 3y ago RHSA-2023:3840: sqlite security update (Moderate)
CVE-2020-17049 medium 5.5 3y ago RHSA-2024:0143: idm:DL1 security update (Moderate)
CVE-2020-36518 medium 5.5 3y ago RHSA-2024:3061: pki-core:10.6 and pki-deps:10.6 security update (Moderate)
CVE-2020-36516 medium 5.5 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2020-28851 medium 5.5 4y ago RHSA-2022:7129: git-lfs security and bug fix update (Moderate)
CVE-2020-28852 medium 5.5 4y ago RHSA-2022:7129: git-lfs security and bug fix update (Moderate)
CVE-2020-0256 medium 5.5 4y ago RHSA-2022:7700: gdisk security update (Moderate)
CVE-2020-36558 medium 5.5 4y ago A race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lead to a NULL pointer dereference and general protection fault.
CVE-2020-10735 medium 5.5 4y ago A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for…
CVE-2020-35525 medium 5.5 4y ago RHSA-2022:7108: sqlite security update (Moderate)
CVE-2020-35527 medium 5.5 4y ago RHSA-2022:7108: sqlite security update (Moderate)
CVE-2020-7788 medium 5.5 4y ago RHSA-2022:0350: nodejs:14 security, bug fix, and enhancement update (Moderate)
CVE-2020-28469 medium 5.5 4y ago RHSA-2022:0350: nodejs:14 security, bug fix, and enhancement update (Moderate)
CVE-2020-35509 medium 5.5 4y ago Keycloak vulnerable to Improper Certificate Validation
CVE-2020-28367 medium 5.5 4y ago RHSA-2020:5493: go-toolset:rhel8 security update (Moderate)
CVE-2020-28366 medium 5.5 4y ago RHSA-2020:5493: go-toolset:rhel8 security update (Moderate)
CVE-2020-29652 medium 5.5 4y ago A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.
CVE-2020-1695 medium 5.5 4y ago RHSA-2021:1775: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (Moderate)
CVE-2020-25864 medium 5.5 4y ago HashiCorp Consul Cross-site Scripting vulnerability in github.com/hashicorp/consul
CVE-2020-24303 medium 5.5 4y ago RHSA-2021:1859: grafana security, bug fix, and enhancement update (Moderate)
CVE-2020-11110 medium 5.5 4y ago RHSA-2020:4682: grafana security, bug fix, and enhancement update (Moderate)
CVE-2020-14019 medium 5.5 4y ago RHEA-2020:4505: python-rtslib bug fix and enhancement update (Moderate)
CVE-2020-10749 medium 5.5 4y ago RHSA-2020:4694: container-tools:rhel8 security, bug fix, and enhancement update (Moderate)
CVE-2020-13430 medium 5.5 4y ago RHSA-2020:4682: grafana security, bug fix, and enhancement update (Moderate)
CVE-2020-12458 medium 5.5 4y ago RHSA-2020:4682: grafana security, bug fix, and enhancement update (Moderate)
CVE-2020-12459 medium 5.5 4y ago RHSA-2020:4682: grafana security, bug fix, and enhancement update (Moderate)
CVE-2020-12245 medium 5.5 4y ago RHSA-2020:4682: grafana security, bug fix, and enhancement update (Moderate)
CVE-2020-1726 medium 5.5 4y ago RHSA-2020:1650: container-tools:rhel8 security, bug fix, and enhancement update (Moderate)
CVE-2020-35492 medium 5.5 4y ago RHSA-2022:1961: cairo and pixman security and bug fix update (Moderate)
CVE-2020-35452 medium 5.5 4y ago Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP …
CVE-2020-19131 medium 5.5 4y ago RHSA-2022:1810: libtiff security update (Moderate)
CVE-2020-18898 medium 5.5 4y ago RHSA-2022:1842: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2020-27826 medium 5.5 4y ago Authentication Bypass in keycloak
CVE-2020-15586 medium 5.5 4y ago RHSA-2020:3665: go-toolset:rhel8 security update (Moderate)
CVE-2020-29509 medium 5.5 4y ago The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that …
CVE-2020-15366 medium 5.5 4y ago RHSA-2021:0551: nodejs:14 security and bug fix update (Moderate)
CVE-2020-11996 medium 5.5 4y ago A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient …
CVE-2020-17527 medium 5.5 4y ago While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream re…
CVE-2020-14366 medium 5.5 4y ago Path Traversal
CVE-2020-11988 medium 5.5 4y ago Server-side request forgery (SSRF) in Apache XmlGraphics Commons
CVE-2020-24553 medium 5.5 4y ago RHSA-2020:5493: go-toolset:rhel8 security update (Moderate)
CVE-2020-11987 medium 5.5 5y ago Server-side request forgery (SSRF) in Apache Batik
CVE-2020-16845 medium 5.5 5y ago RHSA-2020:3665: go-toolset:rhel8 security update (Moderate)
CVE-2020-25719 medium 5.5 5y ago RHSA-2021:5142: idm:DL1 security update (Moderate)
CVE-2020-13435 medium 5.5 5y ago RHSA-2021:4396: sqlite security update (Moderate)
CVE-2020-10001 medium 5.5 5y ago RHSA-2021:4393: cups security and bug fix update (Moderate)
CVE-2020-24870 medium 5.5 5y ago RHSA-2021:4381: GNOME security, bug fix, and enhancement update (Moderate)
CVE-2020-13558 medium 5.5 5y ago A code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A specially crafted web page can lead to a use after free.