2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14106MEDIUM5.5The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi...
CVE-2020-14103MEDIUM5.5The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.
CVE-2020-14104HIGH8.1A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.
CVE-2020-14099HIGH7.5On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backu...
CVE-2020-23539HIGH7.5An issue was discovered in Realtek rtl8723de BLE Stack <= 4.1 that allows remote attackers to cause a Denial of Service ...
CVE-2020-8630Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2020-8629Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2020-8628Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2020-8627Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2020-8626Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2020-23426CRITICAL9.8zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an...
CVE-2020-36316MEDIUM5.5In RELIC before 2021-04-03, there is a buffer overflow in PKCS#1 v1.5 signature verification because garbage bytes can b...
CVE-2020-36315MEDIUM5.3In RELIC before 2020-08-01, RSA PKCS#1 v1.5 signature forgery can occur because certain checks of the padding (and of th...
CVE-2020-24140HIGH8.3Server-side request forgery in Wcms 0.3.2 let an attacker send crafted requests from the back-end server of a vulnerable...
CVE-2020-24139HIGH8.3Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerabl...
CVE-2020-24137MEDIUM5.3Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running...
CVE-2020-24135MEDIUM6.1A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Wcms 0.3.2, which allows remote attackers to inje...
CVE-2020-25584HIGH7.5In FreeBSD 13.0-STABLE before n245118, 12.2-STABLE before r369552, 11.4-STABLE before r369560, 13.0-RC5 before p1, 12.2-...
CVE-2020-24138MEDIUM6.1Cross Site Scripting (XSS) vulnerability in wcms 0.3.2 allows remote attackers to inject arbitrary web script and HTML v...
CVE-2020-24136HIGH8.6Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an applicatio...
CVE-2020-36314LOW3.9fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory...
CVE-2020-11255HIGH7.5Denial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is f...
CVE-2020-11252MEDIUM5.5Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Sna...
CVE-2020-11251CRITICAL9.1Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Sn...
CVE-2020-11247CRITICAL9.1Out of bound memory read while unpacking data due to lack of offset length check in Snapdragon Auto, Snapdragon Compute,...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now