Skip to main content

Year archive

CVEs published in 2020

Archive summary

18,322 CVEs published in 2020 — 2,625 Critical, 7,666 High, 7,546 Medium, 485 Low, 0 Unrated.

CVE-2019-5188

Published Jan 8, 2020

A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on t…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-19518

Published Jan 8, 2020

CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows remote attackers to execute a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17076

Published Jan 8, 2020

An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10778

Published Jan 8, 2020

devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `commonName` controlled by user i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6593

Published Jan 8, 2020

A code-execution vulnerability exists during startup in jhi.dll and otpiha.dll in Symantec VIP Access Desktop before 2.2.2, which could let local malicious users execute arbitrary…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6591

Published Jan 8, 2020

A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabled, which could let a local malicious user bypass security…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6589

Published Jan 8, 2020

A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Suite 8.0.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2072

Published Jan 8, 2020

Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-9908

Published Jan 8, 2020

A Denial of Service vulnerability exists in Google Android 4.4.4, 5.0.2, and 5.1.1, which allows malicious users to block Bluetooh access (Android Bug ID A-28672558).

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20361

Published Jan 8, 2020

There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-20360

Published Jan 8, 2020

A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiable user information (PII) inclu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6163

Published Jan 8, 2020

The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in the templates/search/PropertySu…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17151

Published Jan 7, 2020

This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent WeChat Prior to 7.0.9. User interaction is required to explo…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17148

Published Jan 7, 2020

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (45485). An attacker must first ob…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 18,076-18,100 of 18,322 CVEsPage 724 of 733