2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36126HIGH8.1Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote ...
CVE-2020-36125HIGH7.1Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidat...
CVE-2020-36124MEDIUM6.5Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authentic...
CVE-2020-11295HIGH7.8Use after free in camera If the threadmanager is being cleaned up while the worker thread is processing objects in Snapd...
CVE-2020-11294HIGH7.8Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, S...
CVE-2020-11293MEDIUM6Out of bound read can happen in Widevine TA while copying data to buffer from user data due to lack of check of buffer l...
CVE-2020-11289HIGH7.8Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdrago...
CVE-2020-11288HIGH7.8Out of bound write can occur in playready while processing command due to lack of input validation in Snapdragon Auto, S...
CVE-2020-11285CRITICAL9.1Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in S...
CVE-2020-11284HIGH7.8Locked memory can be unlocked and modified by non secure boot loader through improper system call sequence making the me...
CVE-2020-11279CRITICAL9.8Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdra...
CVE-2020-11274HIGH7.5Denial of service in MODEM due to assert to the invalid configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon...
CVE-2020-11273HIGH7.5Histogram type KPI was teardown with the assumption of the existence of histogram binning info and will lead to null poi...
CVE-2020-11268HIGH7.5Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of servi...
CVE-2020-11254MEDIUM5.5Memory corruption during buffer allocation due to dereferencing session ctx pointer without checking if pointer is valid...
CVE-2020-29445MEDIUM4.3Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify i...
CVE-2020-29444MEDIUM5.4Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javasc...
CVE-2020-23264HIGH8.8Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged...
CVE-2020-23263MEDIUM6.1Persistent Cross-site scripting vulnerability on Fork CMS version 5.8.2 allows remote attackers to inject arbitrary Java...
CVE-2020-28198HIGH7The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe...
CVE-2020-18890CRITICAL9.8Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote maliciou...
CVE-2020-18888HIGH7.5Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /...
CVE-2020-18889MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/setting...
CVE-2020-35519HIGH7.8An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc...
CVE-2020-28026CRITICAL9.8Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now