CVEs from 2020

3,802 normalized CVEs published or assigned in this year.

Total
3,802
critical
critical 206
high
high 563
medium
medium 743
low
low 59
% Critical
5.4%
% with KEV
3.8%
% with exploit
5.4%

Top products

  • retail_xstore_point_of_service 33
  • banking_digital_experience 30
  • primavera_unifier 29
  • retail_service_backbone 15
  • financial_services_institutional_performance_analytics 13
  • insurance_policy_administration_j2ee 11
  • communications_network_charging_and_control 10
  • enterprise_manager_base_platform 10
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-12825 medium 5.5 6y ago RHSA-2020:3654: libcroco security update (Moderate)
CVE-2020-7608 medium 5.5 6y ago RHSA-2021:0548: nodejs:10 security update (Moderate)
CVE-2020-1574 medium 5.5 5.5 6y ago A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitra…
CVE-2020-12402 medium 5.5 6y ago During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perfo…
CVE-2020-8116 medium 5.5 6y ago RHSA-2021:0548: nodejs:10 security update (Moderate)
CVE-2020-14310 medium 5.5 6y ago RHSA-2020:3216: grub2 security update (Moderate)
CVE-2020-15780 medium 5.5 6y ago An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot…
CVE-2020-14308 medium 5.5 6y ago RHSA-2020:3216: grub2 security update (Moderate)
CVE-2020-14309 medium 5.5 6y ago RHSA-2020:3216: grub2 security update (Moderate)
CVE-2020-14311 medium 5.5 6y ago RHSA-2020:3216: grub2 security update (Moderate)
CVE-2020-15705 medium 5.5 6y ago RHSA-2020:3216: grub2 security update (Moderate)
CVE-2020-15706 medium 5.5 6y ago RHSA-2020:3216: grub2 security update (Moderate)
CVE-2020-15707 medium 5.5 6y ago RHSA-2020:3216: grub2 security update (Moderate)
CVE-2020-10713 medium 5.5 6y ago RHSA-2020:3219: kernel-rt security and bug fix update (Moderate)
CVE-2020-1983 medium 5.5 6y ago A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
CVE-2020-10754 medium 5.5 6y ago RHSA-2020:3011: NetworkManager security and bug fix update (Moderate)
CVE-2020-15095 medium 5.5 6y ago Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:…
CVE-2020-15368 medium 5.5 5.5 6y ago AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a request to zero CR3.
CVE-2020-13112 medium 5.5 6y ago RHSA-2020:2550: libexif security update (Moderate)
CVE-2020-13596 medium 5.5 6y ago An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility …
CVE-2020-13254 medium 5.5 6y ago An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collis…
CVE-2020-9547 medium 5.5 6y ago RHSA-2020:1644: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (Moderate)
CVE-2020-10673 medium 5.5 6y ago RHSA-2020:1644: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (Moderate)
CVE-2020-9548 medium 5.5 6y ago RHSA-2020:1644: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (Moderate)
CVE-2020-11501 medium 5.5 6y ago RHSA-2020:1998: gnutls security update (Moderate)
CVE-2020-1702 medium 5.5 6y ago RHSA-2020:1650: container-tools:rhel8 security, bug fix, and enhancement update (Moderate)
CVE-2020-5395 medium 5.5 6y ago RHSA-2020:4844: fontforge security update (Moderate)
CVE-2020-10672 medium 5.5 6y ago RHSA-2020:1644: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (Moderate)
CVE-2020-10663 medium 5.5 6y ago RHSA-2021:2588: ruby:2.6 security, bug fix, and enhancement update (Moderate)
CVE-2020-8840 medium 5.5 6y ago RHSA-2020:1644: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (Moderate)
CVE-2020-1935 medium 5.5 6y ago In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as va…
CVE-2020-7595 medium 5.5 6y ago RHSA-2020:4479: libxml2 security update (Moderate)
CVE-2020-7471 medium 5.5 6y ago Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data …
CVE-2020-37241 medium 5.3 5.3 20d ago bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can…
CVE-2020-8927 medium 5.3 5.3 5y ago RHSA-2022:0830: .NET 5.0 security and bugfix update (Important)
CVE-2020-26146 medium 5.3 5.3 5y ago An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfi…
CVE-2020-27283 medium 5.3 5.3 6y ago An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arbitrary memory locations.
CVE-2020-7549 medium 5.3 5.3 6y ago A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication …
CVE-2020-29372 medium 4.7 4.7 6y ago An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1…
CVE-2020-37217 medium 4.3 4.3 23d ago Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts by tricking authenticated administrators into visiting malicious pages. Attack…
CVE-2020-7568 medium 4.3 4.3 6y ago A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon M221 (all references, all versions) that could allow non sensitive information disclosure when th…
CVE-2020-8166 medium 4.3 4.3 6y ago Ability to forge per-form CSRF tokens in Rails
CVE-2020-8561 medium 4.1 4.1 5y ago A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver re…