2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0428 | MEDIUM | 6.4 | 0.1% | Sep 17, 2020 | In CamX code, there is a possible use after free due to a race condition. This could lead to local escalation of privile... |
| CVE-2020-0427 | MEDIUM | 5.5 | 0.5% | Sep 17, 2020 | In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local in... |
| CVE-2020-0403 | MEDIUM | 6.7 | 0.2% | Sep 17, 2020 | In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This c... |
| CVE-2020-25729 | MEDIUM | 6.1 | 1.2% | Sep 17, 2020 | ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php. |
| CVE-2020-11700 | MEDIUM | 6.5 | 7.1% | Sep 17, 2020 | An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.... |
| CVE-2020-0407 | MEDIUM | 4.4 | 0.1% | Sep 17, 2020 | In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption h... |
| CVE-2020-0404 | MEDIUM | 5.5 | 0.2% | Sep 17, 2020 | In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This... |
| CVE-2020-0399 | MEDIUM | 5.5 | 0.2% | Sep 17, 2020 | In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an un... |
| CVE-2020-0397 | MEDIUM | 5.5 | 0.2% | Sep 17, 2020 | In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe Pen... |
| CVE-2020-0396 | MEDIUM | 5.5 | 0.2% | Sep 17, 2020 | In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to... |
| CVE-2020-0395 | MEDIUM | 5.5 | 0.2% | Sep 17, 2020 | In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due to an unsafe Pending... |
| CVE-2020-0393 | MEDIUM | 5.5 | 0.2% | Sep 17, 2020 | In decrypt and decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. Th... |
| CVE-2020-0390 | MEDIUM | 5.5 | 0.1% | Sep 17, 2020 | In the app zygote SE Policy, there is a possible permissions bypass. This could lead to local information disclosure wit... |
| CVE-2020-0389 | MEDIUM | 5.5 | 0.2% | Sep 17, 2020 | In createSaveNotification of RecordingService.java, there is a possible permission bypass due to an unsafe PendingIntent... |
| CVE-2020-0386 | MEDIUM | 5.5 | 0.4% | Sep 17, 2020 | In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. T... |
| CVE-2020-0385 | MEDIUM | 5.5 | 0.6% | Sep 17, 2020 | In Parse_insh of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead t... |
| CVE-2020-0384 | MEDIUM | 5.5 | 0.6% | Sep 17, 2020 | In Parse_art of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to... |
| CVE-2020-0383 | MEDIUM | 5.5 | 0.6% | Sep 17, 2020 | In Parse_ins of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to re... |
| CVE-2020-0379 | MEDIUM | 5.7 | 0.3% | Sep 17, 2020 | In the Bluetooth service, there is a possible spoofing attack due to a logic error. This could lead to remote informatio... |
| CVE-2020-14338 | MEDIUM | 5.3 | 1.3% | Sep 17, 2020 | A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP... |
| CVE-2020-13944 | MEDIUM | 6.1 | 25.1% | Sep 17, 2020 | In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XS... |
| CVE-2020-14181 | MEDIUM | 5.3 | 99.6% | Sep 17, 2020 | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor... |
| CVE-2020-20406 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 ... |
| CVE-2020-1694 | MEDIUM | 4.9 | 1.6% | Sep 16, 2020 | A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-au... |
| CVE-2020-25015 | MEDIUM | 6.5 | 3.1% | Sep 16, 2020 | A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now