2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0285 | MEDIUM | 5.5 | 0.1% | Sep 18, 2020 | In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local informat... |
| CVE-2020-0284 | MEDIUM | 5.5 | 0.1% | Sep 18, 2020 | In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local informat... |
| CVE-2020-0282 | MEDIUM | 4.5 | 0.6% | Sep 18, 2020 | In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disc... |
| CVE-2020-0281 | MEDIUM | 4.5 | 0.6% | Sep 18, 2020 | In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disc... |
| CVE-2020-0276 | MEDIUM | 5.5 | 0.1% | Sep 18, 2020 | In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local informat... |
| CVE-2020-0272 | MEDIUM | 4.4 | 0.1% | Sep 18, 2020 | In libhwbinder, there is a possible information disclosure due to uninitialized data. This could lead to local informati... |
| CVE-2020-0269 | MEDIUM | 5.5 | 0.1% | Sep 18, 2020 | In Android Auto Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local... |
| CVE-2020-0268 | MEDIUM | 6.4 | 0.1% | Sep 18, 2020 | In NFC, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege wit... |
| CVE-2020-0265 | MEDIUM | 5.5 | 0.1% | Sep 18, 2020 | In Telephony, there are possible leaks of sensitive data due to missing permission checks. This could lead to local info... |
| CVE-2020-0263 | MEDIUM | 5.5 | 0.1% | Sep 18, 2020 | In the Accessibility service, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to l... |
| CVE-2020-7358 | MEDIUM | 6.5 | 0.3% | Sep 18, 2020 | In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the... |
| CVE-2020-15773 | MEDIUM | 6.5 | 0.4% | Sep 18, 2020 | An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only... |
| CVE-2020-0318 | MEDIUM | 5.5 | 0.1% | Sep 18, 2020 | In the System UI, there is a possible system crash due to an uncaught exception. This could lead to local permanent deni... |
| CVE-2020-15774 | MEDIUM | 6.8 | 0.3% | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. An attacker with physical access to the browser of a use... |
| CVE-2020-15772 | MEDIUM | 4.9 | 1.2% | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. When configuring Gradle Enterprise to integrate with a S... |
| CVE-2020-15770 | MEDIUM | 5.5 | 0.3% | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local... |
| CVE-2020-15769 | MEDIUM | 6.1 | 0.7% | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2020.2 - 2020.2.4. An XSS issue exists via the request URL. |
| CVE-2020-15767 | MEDIUM | 5.3 | 0.5% | Sep 18, 2020 | An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not... |
| CVE-2020-5629 | MEDIUM | 6.5 | 1.0% | Sep 18, 2020 | UNIQLO App for Android versions 7.3.3 and earlier allows remote attackers to lead a user to access an arbitrary website ... |
| CVE-2020-5628 | MEDIUM | 6.5 | 1.0% | Sep 18, 2020 | UNIQLO App for Android versions 7.3.3 and earlier allows remote attackers to lead a user to access an arbitrary website ... |
| CVE-2020-5606 | MEDIUM | 6.1 | 0.8% | Sep 18, 2020 | Cross-site scripting vulnerability in WHR-G54S firmware 1.43 and earlier allows remote attackers to inject arbitrary scr... |
| CVE-2020-5605 | MEDIUM | 4.3 | 1.1% | Sep 18, 2020 | Directory traversal vulnerability in WHR-G54S firmware 1.43 and earlier allows an attacker to access sensitive informati... |
| CVE-2020-25735 | MEDIUM | 6.1 | 1.4% | Sep 18, 2020 | webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement... |
| CVE-2020-25734 | MEDIUM | 5.3 | 2.1% | Sep 18, 2020 | webTareas through 2.1 allows files/Default/ Directory Listing. |
| CVE-2020-15187 | MEDIUM | 4.7 | 1.4% | Sep 17, 2020 | In Helm before versions 2.16.11 and 3.3.2, a Helm plugin can contain duplicates of the same entry, with the last one alw... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now