Known vulnerabilities in Ubuntu 20.04 - page 2

Software: Ubuntu
Version: 20.04
Software CPE: cpe:2.3:o:canonical:ubuntu:*:*:*:*:*:*:*:*
Total vulnerabilities: 9617
Public exploits: 343
Known exploited (KEV): 83
Highest CVSSv4 Score: 9.5

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Ubuntu version 20.04 Ubuntu 20.04 is affected by 9617 vulnerabilities: 46 critical, 1238 high, 2888 medium, 5442 low Critical High Medium Low

Vulnerabilities (9617)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144224 - Improper Handling of Exceptional Conditions
CVE-2026-27448
CWE-755 Medium
No
No
- 18.08.2026 SB2026081870
SB2026081877
SB2026081878
and 20 more
#VU135075 - Authentication Bypass by Capture-replay
CVE-2026-11856
CWE-294 Medium
No
No
- 24.06.2026 SB2026062427
SB2026080303
SB2026080441
and 2 more
#VU131921 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2026-40175
CWE-113 Medium
No
No
- 20.05.2026 SB2026052045
SB2026052051
SB2026052052
and 17 more
#VU131563 - Interpretation Conflict
CVE-2026-40930
CWE-436 Medium
No
No
- 15.05.2026 SB2026051550
SB20260529200
SB20260529201
and 2 more
#VU127594 - Permissive List of Allowed Inputs
CVE-2026-42043
CWE-183 Medium
No
No
- 24.04.2026 SB20260424169
SB2026061954
SB2026061999
and 7 more
#VU127593 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-42044
CWE-1321 Medium
No
No
- 24.04.2026 SB20260424168
SB2026062221
SB2026062508
and 5 more
#VU127592 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-42264
CWE-1321 Medium
No
No
- 24.04.2026 SB20260424168
SB2026061999
SB20260619101
and 6 more
#VU125981 - Exposure of sensitive information to an unauthorized actor
CVE-2026-40895
CWE-200 Medium
No
No
- 14.04.2026 SB20260414106
SB2026062434
SB20260625284
and 9 more
#VU125750 - Server-Side Request Forgery (SSRF)
CVE-2025-62718
CWE-918 High
No
No
- 10.04.2026 SB2026041001
SB2026050419
SB2026050715
and 25 more
#VU125602 - Use After Free
CVE-2026-34757
CWE-416 Low
No
No
- 09.04.2026 SB2026040960
SB2026042128
SB20260422224
and 12 more
#VU125601 - Use After Free
CVE-2026-33416
CWE-416 High
No
No
- 09.04.2026 SB2026040959
SB2026040962
SB2026040963
and 59 more
#VU125600 - Out-of-bounds read
CVE-2026-33636
CWE-125 Medium
No
No
- 09.04.2026 SB2026040959
SB2026040962
SB2026040963
and 45 more
#VU119966 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2025-67735
CWE-93 Medium
No
No
- 15.12.2025 SB2025121552
SB2025121974
SB2026012079
and 23 more
#VU86234 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-52138
CWE-22 High
No
No
- 07.02.2024 SB2024020752
SB2024020757
SB2024020758
and 6 more
#VU18304 - Memory corruption
CVE-2018-14048
CWE-119 High
No
No
- 18.04.2019 SB2019041812
SB2019080303
SB2019050660
and 4 more
#VU17708 - Use After Free
CVE-2019-7317
CWE-416 Low
No
No
- 14.02.2019 SB2019011606
SB2019041812
SB2019042401
and 46 more
#VU32000 - Memory corruption
CVE-2016-10128
CWE-119 High
No
No
- 24.03.2017 SB2017032404
SB2017012615
SB2017011506
and 5 more
#VU32001 - NULL Pointer Dereference
CVE-2016-10129
CWE-476 Medium
No
No
- 24.03.2017 SB2017032405
SB2017012616
SB2017011506
and 5 more
#VU32002 - Improper Access Control
CVE-2016-10130
CWE-284 Medium
No
No
- 24.03.2017 SB2017032406
SB2017012617
SB2017011506
and 5 more
#VU39764 - NULL Pointer Dereference
CVE-2016-10087
CWE-476 Medium
No
No
- 31.01.2017 SB2017013107
SB2017010206
SB2017010207
and 15 more


Showing elements 21 - 40 out of 9617