CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

opensuse

backports_sle

326 known vulnerabilities · sorted by CVSS score

CVE-2020-8955
CRITICAL9.8

irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel mode).

weechat / weechat+8
Network
Published Feb 12, 2020
Page 1 of 17
CVE-2019-13962
CRITICAL9.8

lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.

videolan / vlc_media_player+8
Network
Published Jul 18, 2019
CVE-2020-17353
CRITICAL9.8

scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.

lilypond / lilypond+6
Network
Published Aug 5, 2020
CVE-2019-17545
CRITICAL9.8

GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.

osgeo / gdal+9
Network
Published Oct 14, 2019
CVE-2020-12640
CRITICAL9.8

Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

roundcube / webmail+6
Network
Published May 4, 2020
CVE-2020-26935
CRITICAL9.8

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.

phpmyadmin / phpmyadmin+10
Network
Published Oct 10, 2020
CVE-2020-12641
CRITICAL9.8

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

roundcube / webmail+6
Network
Published May 4, 2020
CVE-2020-11800
CRITICAL9.8

Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.

zabbix / zabbix+6
Network
Published Oct 7, 2020
CVE-2019-17455
CRITICAL9.8

Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.

nongnu / libntlm+10
Network
Published Oct 10, 2019
CVE-2019-9215
CRITICAL9.8

In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.

live555 / streaming_media+7
Network
Published Feb 28, 2019
CVE-2019-7164
CRITICAL9.8

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

sqlalchemy / sqlalchemy+17
Network
Published Feb 20, 2019
CVE-2019-18622
CRITICAL9.8

An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.

phpmyadmin / phpmyadmin+6
Network
Published Nov 22, 2019
CVE-2020-15917
CRITICAL9.8

common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.

claws-mail / claws-mail+6
Network
Published Jul 23, 2020
CVE-2020-6469
CRITICAL9.6

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

google / chrome+6
Network
Published May 21, 2020
CVE-2020-6471
CRITICAL9.6

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

google / chrome+6
Network
Published May 21, 2020
CVE-2020-15999
CRITICAL9.6

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google / chrome+5
Network
Published Nov 3, 2020
CVE-2020-16011
CRITICAL9.6

Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

google / chrome+5
Network
Published Nov 3, 2020
CVE-2020-6573
CRITICAL9.6

Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

google / chrome+7
Network
Published Sep 21, 2020
CVE-2020-15963
CRITICAL9.6

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

google / chrome+8
Network
Published Sep 21, 2020
CVE-2020-6466
CRITICAL9.6

Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

google / chrome+6
Network
Published May 21, 2020