CVEs from 2020

3,797 normalized CVEs published or assigned in this year.

Total
3,797
critical
critical 206
high
high 563
medium
medium 745
low
low 59
% Critical
5.4%
% with KEV
3.8%
% with exploit
5.4%

Top products

  • retail_xstore_point_of_service 33
  • banking_digital_experience 30
  • primavera_unifier 29
  • retail_service_backbone 15
  • financial_services_institutional_performance_analytics 13
  • insurance_policy_administration_j2ee 11
  • communications_network_charging_and_control 10
  • enterprise_manager_base_platform 10
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-20448 low 2.5 FFmpeg 4.1.3 is affected by a Divide By Zero issue via libavcodec/ratecontrol.c, which allows a remote malicious user to cause a Denial of Service.
CVE-2020-18974 low 2.5 Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147.
CVE-2020-21710 low 2.5 2y ago RHSA-2024:2966: ghostscript security update (Low)
CVE-2020-23903 low 2.5 4y ago Low: speex security update
CVE-2020-13950 low 2.5 4y ago Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, le…
CVE-2020-22083 low 2.5 4y ago ** DISPUTED ** jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and cl…
CVE-2020-17489 low 2.5 4y ago An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible…
CVE-2020-24370 low 2.5 5y ago RHSA-2021:4510: lua security update (Low)
CVE-2020-16135 low 2.5 5y ago RHSA-2021:4387: libssh security update (Low)
CVE-2020-14155 low 2.5 5y ago RHSA-2021:4373: pcre security update (Low)
CVE-2020-18442 low 2.5 5y ago RHSA-2021:4316: zziplib security update (Low)
CVE-2020-8037 low 2.5 5y ago RHSA-2021:4236: tcpdump security and bug fix update (Low)
CVE-2020-36314 low 2.5 5y ago RHSA-2021:4179: file-roller security update (Low)
CVE-2020-13987 low 2.5 5y ago RHBA-2021:4446: iscsi-initiator-utils bug fix and enhancement update (Low)
CVE-2020-16117 low 2.5 5y ago RHSA-2021:1752: evolution security, bug fix, and enhancement update (Low)
CVE-2020-36318 low 2.5 5y ago In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use-after-free or doub…
CVE-2020-36317 low 2.5 5y ago In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation of a non-UTF-8 Rust string when the provided closure panics. This bug could res…
CVE-2020-29651 low 2.5 5y ago A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying …
CVE-2020-11736 low 2.5 6y ago RHSA-2021:4179: file-roller security update (Low)
CVE-2020-3898 low 2.5 6y ago RHSA-2020:4469: cups security and bug fix update (Low)
CVE-2020-14928 low 2.5 6y ago RHSA-2020:4649: evolution security and bug fix update (Low)
CVE-2020-12802 low 2.5 6y ago LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who w…
CVE-2020-12803 low 2.5 6y ago ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable f…
CVE-2020-10759 low 2.5 6y ago A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practi…
CVE-2020-11078 low 2.5 6y ago RHSA-2020:4605: resource-agents security and bug fix update (Low)
CVE-2020-11054 low 2.5 6y ago In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (col…
CVE-2020-15719 low 2.5 7y ago RHBA-2019:3674: openldap bug fix and enhancement update (Low)
CVE-2020-8562 low 2.2 2.2 4y ago As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Servi…