2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-0089HIGH7.8In the audio server, there is a missing permission check. This could lead to local escalation of privilege regarding aud...
CVE-2020-15776HIGH8.8An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie ...
CVE-2020-15775HIGH7.5An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level ...
CVE-2020-15771HIGH7.5An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission ...
CVE-2020-15768HIGH7.5An issue was discovered in Gradle Enterprise 2017.3 - 2020.2.4 and Gradle Enterprise Build Cache Node 1.0 - 9.2. Unrestr...
CVE-2020-25751HIGH8.8The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=c...
CVE-2020-25750HIGH7.5An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is ...
CVE-2020-25744HIGH8.1SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could ...
CVE-2020-25733HIGH7.5webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
CVE-2020-0406HIGH7.8In libmpeg2dec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalati...
CVE-2020-0375HIGH7.8In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalati...
CVE-2020-0374HIGH7.8In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of pri...
CVE-2020-0369HIGH7.8In libavb, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of pr...
CVE-2020-0366HIGH7.8In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability. This could lead to local ...
CVE-2020-0360HIGH7.8In Notification Access Confirmation, there is a possible permissions bypass due to uninformed consent. This could lead t...
CVE-2020-0357HIGH7.8In SurfaceFlinger, there is a possible use-after-free due to improper locking. This could lead to local escalation of pr...
CVE-2020-0346HIGH7.8In Mediaserver, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation ...
CVE-2020-0345HIGH7.8In DocumentsUI, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of p...
CVE-2020-0341HIGH7.8In DisplayManager, there is a possible permission bypass due to a missing permission check. This could lead to local esc...
CVE-2020-0321HIGH8.8In the mp3 extractor, there is a possible out of bounds write due to uninitialized data. This could lead to remote code ...
CVE-2020-0306HIGH7.8In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservation. This could lead t...
CVE-2020-0303HIGH8.8In the Media extractor, there is a possible use after free due to improper locking. This could lead to remote code execu...
CVE-2020-0277HIGH7.8In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission check. This could lea...
CVE-2020-0275HIGH7.8In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access...
CVE-2020-0267HIGH7.8In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local esc...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now