2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-0254HIGH7.5There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID:...
CVE-2020-0251HIGH7.5There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID:...
CVE-2020-0243HIGH7.8In clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper locking. This could lead...
CVE-2020-0242HIGH7.8In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local esc...
CVE-2020-0241HIGH7.8In NuPlayerStreamListener of NuPlayerStreamListener.cpp, there is possible memory corruption due to a double free. This ...
CVE-2020-0240HIGH8.8In NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer overflow. This could lea...
CVE-2020-0238HIGH7In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race cond...
CVE-2020-0108HIGH7.8In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncau...
CVE-2020-9404HIGH7.1In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in an insecure manner, and may be modified by a...
CVE-2020-8918HIGH7.1An improperly initialized 'migrationAuth' value in Google's go-tpm TPM1.2 library versions prior to 0.3.0 can lead an ea...
CVE-2020-11976HIGH7.5By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker...
CVE-2020-14979HIGH7.8The WinRing0.sys and WinRing0x64.sys drivers 1.2.0 in EVGA Precision X1 through 1.0.6 allow local users, including low i...
CVE-2020-13177HIGH7.8The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04....
CVE-2020-13175HIGH7.5The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to ...
CVE-2020-17448HIGH7.8Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechan...
CVE-2020-17367HIGH7.8Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to comm...
CVE-2020-13124HIGH8.8SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an a...
CVE-2020-14296HIGH7.1Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible T...
CVE-2020-10783HIGH8.3Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group ...
CVE-2020-4486HIGH8.1IBM QRadar 7.2.0 thorugh 7.2.9 could allow an authenticated user to overwrite or delete arbitrary files due to a flaw af...
CVE-2020-9079HIGH8.8FusionSphere OpenStack 8.0.0 have a protection mechanism failure vulnerability. The product incorrectly uses a protectio...
CVE-2020-16277HIGH8.8An SQL injection vulnerability in the Analytics component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, au...
CVE-2020-16276HIGH8.8An SQL injection vulnerability in the Assets component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authe...
CVE-2020-9078HIGH7.8FusionCompute 8.0.0 have local privilege escalation vulnerability. A local, authenticated attacker could perform specifi...
CVE-2020-17478HIGH7.5ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplicati...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now