2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11226HIGH7.5Out of bound memory read in Data modem while unpacking data due to lack of offset length check in Snapdragon Auto, Snapd...
CVE-2020-11222CRITICAL9.1Buffer over read while processing MT SMS with maximum length due to improper length check in Snapdragon Auto, Snapdragon...
CVE-2020-11221MEDIUM5.5Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due ...
CVE-2020-11220MEDIUM6.4While processing storage SCM commands there is a time of check or time of use window where a pointer used could be inval...
CVE-2020-11218HIGH7.5Denial of service in baseband when NW configures LTE betaOffset-RI-Index due to lack of data validation in Snapdragon Au...
CVE-2020-11199MEDIUM5.5HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information e...
CVE-2020-11192CRITICAL9.8Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Comp...
CVE-2020-11190CRITICAL9.1Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon...
CVE-2020-11189CRITICAL9.1Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon...
CVE-2020-11188CRITICAL9.1Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon...
CVE-2020-11186MEDIUM5.5Modem will enter into busy mode in an infinite loop while parsing histogram dimension due to improper validation of inpu...
CVE-2020-11171CRITICAL9.1Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon...
CVE-2020-11166CRITICAL9.1Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC...
CVE-2020-28899CRITICAL9.1The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote un...
CVE-2020-24264CRITICAL9.8Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. T...
CVE-2020-24263HIGH8.8Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code...
CVE-2020-4891MEDIUM5.5IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could...
CVE-2020-4890MEDIUM4.4IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user with a valid role to the RES...
CVE-2020-4851MEDIUM5.5IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which co...
CVE-2020-1926MEDIUM5.9Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing ...
CVE-2020-27290MEDIUM4.3In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilato...
CVE-2020-27282MEDIUM4.3In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in the ventilator allows...
CVE-2020-27278MEDIUM5.2In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, hard-coded credentials in the ventilator allow attackers...
CVE-2020-29553HIGH8.8The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into v...
CVE-2020-29556MEDIUM5.5The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now