2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11246HIGH7.8A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapd...
CVE-2020-11245HIGH7.8Unintended reads and writes by NS EL2 in access control driver due to lack of check of input validation in Snapdragon Au...
CVE-2020-11243HIGH7.5RRC sends a connection establishment success to NAS even though connection setup validation returns failure and leads to...
CVE-2020-11242HIGH7.8User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to captu...
CVE-2020-11237HIGH7.8Memory crash when accessing histogram type KPI input received due to lack of check of histogram definition before access...
CVE-2020-11236MEDIUM5.5Memory corruption due to invalid value of total dimension in the non-histogram type KPI could lead to a denial of servic...
CVE-2020-11234HIGH7.8When sending a socket event message to a user application, invalid information will be passed if socket is freed by othe...
CVE-2020-11231MEDIUM6.7Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in tu...
CVE-2020-11210HIGH8.8Possible memory corruption in RPM region due to improper XPU configuration in Snapdragon Connectivity, Snapdragon Indust...
CVE-2020-11191CRITICAL9.1Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon...
CVE-2020-36313HIGH7.8An issue was discovered in the Linux kernel before 5.7. The KVM subsystem allows out-of-range access to memslots after a...
CVE-2020-36312MEDIUM5.5An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory le...
CVE-2020-36311MEDIUM5.5An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of ser...
CVE-2020-36310MEDIUM5.5An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite ...
CVE-2020-13422HIGH8.1OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative action...
CVE-2020-13421CRITICAL9.8OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset act...
CVE-2020-13420CRITICAL9.8OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script.
CVE-2020-13419MEDIUM5.3OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task.
CVE-2020-13418MEDIUM6.1OpenIAM before 4.2.0.3 allows XSS in the Add New User feature.
CVE-2020-36309MEDIUM5.3ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when usin...
CVE-2020-36285HIGH7.5Union Pay up to 3.3.12, for iOS mobile apps, contains a CWE-347: Improper Verification of Cryptographic Signature vulner...
CVE-2020-36284HIGH7.5Union Pay up to 3.4.93.4.9, for android, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerabil...
CVE-2020-23533HIGH7.5Union Pay up to 1.2.0, for web based versions contains a CWE-347: Improper Verification of Cryptographic Signature vulne...
CVE-2020-36308MEDIUM5.3Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performin...
CVE-2020-36307MEDIUM6.1Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now