2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11194HIGH7.8Possible out of bound access in TA while processing a command from NS side due to improper length check of response buff...
CVE-2020-11187HIGH7.8Possible memory corruption in BSI module due to improper validation of parameter count in Snapdragon Auto, Snapdragon Co...
CVE-2020-11177HIGH8.8User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and ...
CVE-2020-11170CRITICAL9.8Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header ex...
CVE-2020-11163CRITICAL9.8Possible buffer overflow while updating ikev2 parameters due to lack of check of input validation for certain parameters...
CVE-2020-11147MEDIUM6.7Use after free issue in audio modules while removing and freeing objects during list iteration due to incorrect usage of...
CVE-2020-35681HIGH7.4Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope....
CVE-2020-35664MEDIUM6.1An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in ...
CVE-2020-35571MEDIUM6.1An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.ph...
CVE-2020-35556HIGH7.5An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service ...
CVE-2020-28248HIGH8.8An integer overflow in the PngImg::InitStorage_() function of png-img before 3.1.0 leads to an under-allocation of heap ...
CVE-2020-27997HIGH8.8An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to ...
CVE-2020-24617HIGH8.8Mailtrain through 1.24.1 allows SQL Injection in statsClickedSubscribersByColumn in lib/models/campaigns.js via /campaig...
CVE-2020-24393MEDIUM5.9TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allo...
CVE-2020-24392MEDIUM5.9In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attac...
CVE-2020-12873HIGH8.8An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a F...
CVE-2020-12668MEDIUM6.5Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context....
CVE-2020-27785Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-29074. Reason: This candidate is a reservation d...
CVE-2020-35499MEDIUM6.7A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in ne...
CVE-2020-9050HIGH7.5Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenti...
CVE-2020-25171HIGH7.8The affected Fuji Electric V-Server Lite versions prior to 3.3.24.0 are vulnerable to an out-of-bounds write, which may ...
CVE-2020-13549HIGH7.8An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0...
CVE-2020-12374MEDIUM6.7Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2...
CVE-2020-36248MEDIUM4.6The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a bac...
CVE-2020-36252MEDIUM5.7ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version o...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now