CVEs from 2020
Total
3,802
critical
critical 206
high
high 563
medium
medium 743
low
low 59
% Critical
5.4%
% with KEV
3.8%
% with exploit
5.4%
Top vendors
- oracle 476
- schneider-electric 139
- siemens 103
- netapp 28
- arista 15
- rockwellautomation 9
- fasterxml 8
- kubernetes 8
Top products
- retail_xstore_point_of_service 33
- banking_digital_experience 30
- primavera_unifier 29
- retail_service_backbone 15
- financial_services_institutional_performance_analytics 13
- insurance_policy_administration_j2ee 11
- communications_network_charging_and_control 10
- enterprise_manager_base_platform 10
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-27918 | medium | — | 5.5 | 5y ago | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS … | |||
| CVE-2020-29623 | medium | — | 5.5 | 5y ago | "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security… | |||
| CVE-2020-24870 | medium | — | 5.5 | 5y ago | RHSA-2021:4381: GNOME security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14145 | medium | — | 5.5 | 5y ago | The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connect… | |||
| CVE-2020-35448 | medium | — | 5.5 | 5y ago | RHSA-2021:4364: binutils security update (Moderate) | |||
| CVE-2020-13529 | medium | — | 5.5 | 5y ago | An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing att… | |||
| CVE-2020-26143 | medium | — | 5.5 | 5y ago | RHSA-2021:4356: kernel security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-27777 | medium | — | 5.5 | 5y ago | A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors … | |||
| CVE-2020-24503 | medium | — | 5.5 | 5y ago | RHSA-2021:4356: kernel security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-24504 | medium | — | 5.5 | 5y ago | Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable denial of service via local acces… | |||
| CVE-2020-24588 | medium | — | 5.5 | 5y ago | The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authentica… | |||
| CVE-2020-26139 | medium | — | 5.5 | 5y ago | An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be… | |||
| CVE-2020-26140 | medium | — | 5.5 | 5y ago | RHSA-2021:4356: kernel security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-26144 | medium | — | 5.5 | 5y ago | RHSA-2021:4356: kernel security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-29368 | medium | — | 5.5 | 5y ago | An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a T… | |||
| CVE-2020-36158 | medium | — | 5.5 | 5y ago | mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID… | |||
| CVE-2020-29660 | medium | — | 5.5 | 5y ago | A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIO… | |||
| CVE-2020-36312 | medium | — | 5.5 | 5y ago | An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory leak upon a kmalloc failure, aka CID-f65886606c2d. | |||
| CVE-2020-36386 | medium | — | 5.5 | 5y ago | An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci_extended_inquiry_result_evt, aka CID-51c19bf3d5cf. | |||
| CVE-2020-26147 | medium | — | 5.5 | 5y ago | An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused … | |||
| CVE-2020-26145 | medium | — | 5.5 | 5y ago | An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and proces… | |||
| CVE-2020-24502 | medium | — | 5.5 | 5y ago | RHSA-2021:4356: kernel security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-26141 | medium | — | 5.5 | 5y ago | An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adver… | |||
| CVE-2020-0427 | medium | — | 5.5 | 5y ago | In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User inter… | |||
| CVE-2020-24586 | medium | — | 5.5 | 5y ago | The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting … | |||
| CVE-2020-24587 | medium | — | 5.5 | 5y ago | The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An a… | |||
| CVE-2020-1946 | medium | — | 5.5 | 5y ago | RHSA-2021:4315: spamassassin security update (Moderate) | |||
| CVE-2020-17541 | medium | — | 5.5 | 5y ago | RHSA-2021:4288: libjpeg-turbo security and bug fix update (Moderate) | |||
| CVE-2020-18032 | medium | — | 5.5 | 5y ago | RHSA-2021:4256: graphviz security update (Moderate) | |||
| CVE-2020-27823 | medium | — | 5.5 | 5y ago | RHSA-2021:4251: openjpeg2 security update (Moderate) | |||
| CVE-2020-15389 | medium | — | 5.5 | 5y ago | RHSA-2021:4251: openjpeg2 security update (Moderate) | |||
| CVE-2020-27814 | medium | — | 5.5 | 5y ago | RHSA-2021:4251: openjpeg2 security update (Moderate) | |||
| CVE-2020-27842 | medium | — | 5.5 | 5y ago | RHSA-2021:4251: openjpeg2 security update (Moderate) | |||
| CVE-2020-27845 | medium | — | 5.5 | 5y ago | RHSA-2021:4251: openjpeg2 security update (Moderate) | |||
| CVE-2020-27824 | medium | — | 5.5 | 5y ago | RHSA-2021:4251: openjpeg2 security update (Moderate) | |||
| CVE-2020-27843 | medium | — | 5.5 | 5y ago | RHSA-2021:4251: openjpeg2 security update (Moderate) | |||
| CVE-2020-35522 | medium | — | 5.5 | 5y ago | RHSA-2021:4241: libtiff security and bug fix update (Moderate) | |||
| CVE-2020-35524 | medium | — | 5.5 | 5y ago | RHSA-2021:4241: libtiff security and bug fix update (Moderate) | |||
| CVE-2020-35523 | medium | — | 5.5 | 5y ago | RHSA-2021:4241: libtiff security and bug fix update (Moderate) | |||
| CVE-2020-35521 | medium | — | 5.5 | 5y ago | RHSA-2021:4241: libtiff security and bug fix update (Moderate) | |||
| CVE-2020-27828 | medium | — | 5.5 | 5y ago | RHSA-2021:4235: jasper security update (Moderate) | |||
| CVE-2020-36330 | medium | — | 5.5 | 5y ago | RHSA-2021:4231: libwebp security update (Moderate) | |||
| CVE-2020-36332 | medium | — | 5.5 | 5y ago | RHSA-2021:4231: libwebp security update (Moderate) | |||
| CVE-2020-36331 | medium | — | 5.5 | 5y ago | RHSA-2021:4231: libwebp security update (Moderate) | |||
| CVE-2020-7069 | medium | — | 5.5 | 5y ago | RHSA-2021:4213: php:7.4 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-7070 | medium | — | 5.5 | 5y ago | RHSA-2021:4213: php:7.4 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-7071 | medium | — | 5.5 | 5y ago | RHSA-2021:4213: php:7.4 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-7068 | medium | — | 5.5 | 5y ago | RHSA-2021:4213: php:7.4 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-15859 | medium | — | 5.5 | 5y ago | QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address. | |||
| CVE-2020-28896 | medium | — | 5.5 | 5y ago | RHSA-2021:4181: mutt security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-27619 | medium | — | 5.5 | 5y ago | In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP. | |||
| CVE-2020-26558 | medium | — | 5.5 | 5y ago | Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authe… | |||
| CVE-2020-14873 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14888 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14891 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14893 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14860 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14852 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14848 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14846 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14861 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14867 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14866 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14868 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14870 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14844 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14769 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14830 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14829 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14838 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14828 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14765 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14845 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14773 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14839 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14836 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14785 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14794 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14775 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14777 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14672 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14821 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14837 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14814 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14809 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14804 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14793 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14790 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14800 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14791 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-14786 | medium | — | 5.5 | 5y ago | RHSA-2021:3590: mysql:8.0 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-25648 | medium | — | 5.5 | 5y ago | A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled … | |||
| CVE-2020-13754 | medium | — | 5.5 | 5y ago | hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation. | |||
| CVE-2020-27617 | medium | — | 5.5 | 5y ago | eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol. | |||
| CVE-2020-36323 | medium | — | 5.5 | 5y ago | RHSA-2021:3063: rust-toolset:rhel8 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-26264 | medium | — | 5.5 | 5y ago | Nil pointer dereference via malicious RPC message in github.com/ethereum/go-ethereum | |||
| CVE-2020-10933 | medium | — | 5.5 | 5y ago | RHSA-2021:2588: ruby:2.6 security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-27846 | medium | — | 5.5 | 5y ago | RHSA-2021:1859: grafana security, bug fix, and enhancement update (Moderate) | |||
| CVE-2020-26284 | medium | — | 5.5 | 5y ago | Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system `%… | |||
| CVE-2020-26137 | medium | — | 5.5 | 5y ago | RHSA-2021:1761: python27:2.7 security and bug fix update (Moderate) |