2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11226 | HIGH | 7.5 | 0.9% | Mar 17, 2021 | Out of bound memory read in Data modem while unpacking data due to lack of offset length check in Snapdragon Auto, Snapd... |
| CVE-2020-11222 | CRITICAL | 9.1 | 0.9% | Mar 17, 2021 | Buffer over read while processing MT SMS with maximum length due to improper length check in Snapdragon Auto, Snapdragon... |
| CVE-2020-11221 | MEDIUM | 5.5 | 0.2% | Mar 17, 2021 | Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due ... |
| CVE-2020-11220 | MEDIUM | 6.4 | 0.1% | Mar 17, 2021 | While processing storage SCM commands there is a time of check or time of use window where a pointer used could be inval... |
| CVE-2020-11218 | HIGH | 7.5 | 0.8% | Mar 17, 2021 | Denial of service in baseband when NW configures LTE betaOffset-RI-Index due to lack of data validation in Snapdragon Au... |
| CVE-2020-11199 | MEDIUM | 5.5 | 0.2% | Mar 17, 2021 | HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information e... |
| CVE-2020-11192 | CRITICAL | 9.8 | 1.1% | Mar 17, 2021 | Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Comp... |
| CVE-2020-11190 | CRITICAL | 9.1 | 1.0% | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon... |
| CVE-2020-11189 | CRITICAL | 9.1 | 1.0% | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon... |
| CVE-2020-11188 | CRITICAL | 9.1 | 1.0% | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon... |
| CVE-2020-11186 | MEDIUM | 5.5 | 0.2% | Mar 17, 2021 | Modem will enter into busy mode in an infinite loop while parsing histogram dimension due to improper validation of inpu... |
| CVE-2020-11171 | CRITICAL | 9.1 | 1.0% | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon... |
| CVE-2020-11166 | CRITICAL | 9.1 | 0.9% | Mar 17, 2021 | Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC... |
| CVE-2020-28899 | CRITICAL | 9.1 | 1.6% | Mar 16, 2021 | The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote un... |
| CVE-2020-24264 | CRITICAL | 9.8 | 4.1% | Mar 16, 2021 | Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. T... |
| CVE-2020-24263 | HIGH | 8.8 | 1.6% | Mar 16, 2021 | Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code... |
| CVE-2020-4891 | MEDIUM | 5.5 | 0.2% | Mar 16, 2021 | IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could... |
| CVE-2020-4890 | MEDIUM | 4.4 | 0.2% | Mar 16, 2021 | IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user with a valid role to the RES... |
| CVE-2020-4851 | MEDIUM | 5.5 | 0.3% | Mar 16, 2021 | IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which co... |
| CVE-2020-1926 | MEDIUM | 5.9 | 2.5% | Mar 16, 2021 | Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing ... |
| CVE-2020-27290 | MEDIUM | 4.3 | 0.3% | Mar 15, 2021 | In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilato... |
| CVE-2020-27282 | MEDIUM | 4.3 | 0.3% | Mar 15, 2021 | In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in the ventilator allows... |
| CVE-2020-27278 | MEDIUM | 5.2 | 0.3% | Mar 15, 2021 | In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, hard-coded credentials in the ventilator allow attackers... |
| CVE-2020-29553 | HIGH | 8.8 | 1.4% | Mar 15, 2021 | The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into v... |
| CVE-2020-29556 | MEDIUM | 5.5 | 1.0% | Mar 15, 2021 | The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now