2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36126 | HIGH | 8.1 | 1.4% | May 7, 2021 | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote ... |
| CVE-2020-36125 | HIGH | 7.1 | 0.9% | May 7, 2021 | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidat... |
| CVE-2020-36124 | MEDIUM | 6.5 | 1.3% | May 7, 2021 | Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authentic... |
| CVE-2020-11295 | HIGH | 7.8 | 0.1% | May 7, 2021 | Use after free in camera If the threadmanager is being cleaned up while the worker thread is processing objects in Snapd... |
| CVE-2020-11294 | HIGH | 7.8 | 0.1% | May 7, 2021 | Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, S... |
| CVE-2020-11293 | MEDIUM | 6 | 0.1% | May 7, 2021 | Out of bound read can happen in Widevine TA while copying data to buffer from user data due to lack of check of buffer l... |
| CVE-2020-11289 | HIGH | 7.8 | 0.2% | May 7, 2021 | Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdrago... |
| CVE-2020-11288 | HIGH | 7.8 | 0.2% | May 7, 2021 | Out of bound write can occur in playready while processing command due to lack of input validation in Snapdragon Auto, S... |
| CVE-2020-11285 | CRITICAL | 9.1 | 0.9% | May 7, 2021 | Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in S... |
| CVE-2020-11284 | HIGH | 7.8 | 0.2% | May 7, 2021 | Locked memory can be unlocked and modified by non secure boot loader through improper system call sequence making the me... |
| CVE-2020-11279 | CRITICAL | 9.8 | 0.8% | May 7, 2021 | Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdra... |
| CVE-2020-11274 | HIGH | 7.5 | 0.7% | May 7, 2021 | Denial of service in MODEM due to assert to the invalid configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon... |
| CVE-2020-11273 | HIGH | 7.5 | 0.7% | May 7, 2021 | Histogram type KPI was teardown with the assumption of the existence of histogram binning info and will lead to null poi... |
| CVE-2020-11268 | HIGH | 7.5 | 0.7% | May 7, 2021 | Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of servi... |
| CVE-2020-11254 | MEDIUM | 5.5 | 0.1% | May 7, 2021 | Memory corruption during buffer allocation due to dereferencing session ctx pointer without checking if pointer is valid... |
| CVE-2020-29445 | MEDIUM | 4.3 | 1.2% | May 7, 2021 | Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify i... |
| CVE-2020-29444 | MEDIUM | 5.4 | 0.9% | May 7, 2021 | Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javasc... |
| CVE-2020-23264 | HIGH | 8.8 | 0.6% | May 6, 2021 | Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged... |
| CVE-2020-23263 | MEDIUM | 6.1 | 0.8% | May 6, 2021 | Persistent Cross-site scripting vulnerability on Fork CMS version 5.8.2 allows remote attackers to inject arbitrary Java... |
| CVE-2020-28198 | HIGH | 7 | 0.4% | May 6, 2021 | The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe... |
| CVE-2020-18890 | CRITICAL | 9.8 | 1.5% | May 6, 2021 | Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote maliciou... |
| CVE-2020-18888 | HIGH | 7.5 | 0.8% | May 6, 2021 | Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /... |
| CVE-2020-18889 | MEDIUM | 6.5 | 0.5% | May 6, 2021 | Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/setting... |
| CVE-2020-35519 | HIGH | 7.8 | 0.4% | May 6, 2021 | An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc... |
| CVE-2020-28026 | CRITICAL | 9.8 | 9.3% | May 6, 2021 | Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now