2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-8332MEDIUM6.4A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo an...
CVE-2020-7318MEDIUM4.3Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10.9 Update 9 allows administrators t...
CVE-2020-7317MEDIUM4.3Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows administrators t...
CVE-2020-3483MEDIUM6.3Duo has identified and fixed an issue with the Duo Network Gateway (DNG) product in which some customer-provided SSL cer...
CVE-2020-15253MEDIUM4.8Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via the Create Shopping List module, that is rendered ...
CVE-2020-15224MEDIUM6.8In Open Enclave before version 0.12.0, an information disclosure vulnerability exists when an enclave application using ...
CVE-2020-4395MEDIUM5.4IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated ...
CVE-2020-27013MEDIUM4.4Trend Micro Antivirus for Mac 2020 (Consumer) contains a vulnerability in the product that occurs when a webserver is st...
CVE-2020-25778MEDIUM6Trend Micro Antivirus for Mac 2020 (Consumer) has a vulnerability in a specific kernel extension where an attacker could...
CVE-2020-25777MEDIUM5.4Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a specific kernel extension request attack where an attac...
CVE-2020-24188MEDIUM6.1Cross-site scripting (XSS) vulnerability in the search functionality in Intrexx before 9.4.0 allows remote attackers to ...
CVE-2020-6933MEDIUM5.5An improper input validation vulnerability in the UEM Core of BlackBerry UEM version(s) 12.13.0, 12.12.1a QF2 (and earli...
CVE-2020-0419MEDIUM5.5In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installat...
CVE-2020-0415MEDIUM5.5In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent. This could lead ...
CVE-2020-0414MEDIUM6.5In AudioFlinger::RecordThread::threadLoop of audioflinger/Threads.cpp, there is a possible non-silenced audio buffer due...
CVE-2020-0411MEDIUM6.5In ~AACExtractor() of AACExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could le...
CVE-2020-0410MEDIUM5.5In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent error. This could lea...
CVE-2020-0400MEDIUM5.5In showDataRoamingNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIn...
CVE-2020-0398MEDIUM5.5In updateMwi of NotificationMgr.java, there is a possible permission bypass due to a PendingIntent error. This could lea...
CVE-2020-0378MEDIUM5.5In onWnmFrameReceived of PasspointManager.java, there is a missing permission check. This could lead to local informatio...
CVE-2020-0246MEDIUM5.5In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check. This could lead to local infor...
CVE-2020-24551MEDIUM6.1IProom MMC+ Server login page does not validate specific parameters properly. Attackers can use the vulnerability to red...
CVE-2020-12933MEDIUM5.5A denial of service vulnerability exists in the D3DKMTEscape handler functionality of AMD ATIKMDAG.SYS (e.g. version 26....
CVE-2020-12911MEDIUM5.5A denial of service vulnerability exists in the D3DKMTCreateAllocation handler functionality of AMD ATIKMDAG.SYS (e.g. v...
CVE-2020-15251MEDIUM6.5In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now