2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11194 | HIGH | 7.8 | 0.2% | Feb 22, 2021 | Possible out of bound access in TA while processing a command from NS side due to improper length check of response buff... |
| CVE-2020-11187 | HIGH | 7.8 | 0.2% | Feb 22, 2021 | Possible memory corruption in BSI module due to improper validation of parameter count in Snapdragon Auto, Snapdragon Co... |
| CVE-2020-11177 | HIGH | 8.8 | 0.2% | Feb 22, 2021 | User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and ... |
| CVE-2020-11170 | CRITICAL | 9.8 | 0.8% | Feb 22, 2021 | Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header ex... |
| CVE-2020-11163 | CRITICAL | 9.8 | 0.8% | Feb 22, 2021 | Possible buffer overflow while updating ikev2 parameters due to lack of check of input validation for certain parameters... |
| CVE-2020-11147 | MEDIUM | 6.7 | 0.2% | Feb 22, 2021 | Use after free issue in audio modules while removing and freeing objects during list iteration due to incorrect usage of... |
| CVE-2020-35681 | HIGH | 7.4 | 2.7% | Feb 22, 2021 | Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope.... |
| CVE-2020-35664 | MEDIUM | 6.1 | 0.7% | Feb 22, 2021 | An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in ... |
| CVE-2020-35571 | MEDIUM | 6.1 | 0.7% | Feb 22, 2021 | An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.ph... |
| CVE-2020-35556 | HIGH | 7.5 | 1.0% | Feb 22, 2021 | An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service ... |
| CVE-2020-28248 | HIGH | 8.8 | 2.2% | Feb 20, 2021 | An integer overflow in the PngImg::InitStorage_() function of png-img before 3.1.0 leads to an under-allocation of heap ... |
| CVE-2020-27997 | HIGH | 8.8 | 0.8% | Feb 19, 2021 | An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to ... |
| CVE-2020-24617 | HIGH | 8.8 | 1.5% | Feb 19, 2021 | Mailtrain through 1.24.1 allows SQL Injection in statsClickedSubscribersByColumn in lib/models/campaigns.js via /campaig... |
| CVE-2020-24393 | MEDIUM | 5.9 | 0.9% | Feb 19, 2021 | TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allo... |
| CVE-2020-24392 | MEDIUM | 5.9 | 0.9% | Feb 19, 2021 | In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attac... |
| CVE-2020-12873 | HIGH | 8.8 | 1.6% | Feb 19, 2021 | An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a F... |
| CVE-2020-12668 | MEDIUM | 6.5 | 1.8% | Feb 19, 2021 | Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context.... |
| CVE-2020-27785 | — | — | — | Feb 19, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-29074. Reason: This candidate is a reservation d... |
| CVE-2020-35499 | MEDIUM | 6.7 | 0.3% | Feb 19, 2021 | A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in ne... |
| CVE-2020-9050 | HIGH | 7.5 | 2.1% | Feb 19, 2021 | Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenti... |
| CVE-2020-25171 | HIGH | 7.8 | 1.0% | Feb 19, 2021 | The affected Fuji Electric V-Server Lite versions prior to 3.3.24.0 are vulnerable to an out-of-bounds write, which may ... |
| CVE-2020-13549 | HIGH | 7.8 | 0.5% | Feb 19, 2021 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0... |
| CVE-2020-12374 | MEDIUM | 6.7 | 0.3% | Feb 19, 2021 | Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2... |
| CVE-2020-36248 | MEDIUM | 4.6 | 0.1% | Feb 19, 2021 | The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a bac... |
| CVE-2020-36252 | MEDIUM | 5.7 | 0.5% | Feb 19, 2021 | ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version o... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now