2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-3665HIGH7.8A possible buffer overflow would occur while processing command from firmware due to the group_id obtained from the firm...
CVE-2020-3642HIGH7.8Use after free issue in camera applications when used randomly over multiple operations due to pointer not set to NULL a...
CVE-2020-3635HIGH7.8Stack based overflow If the maximum number of arguments allowed per request in perflock exceeds in Snapdragon Auto, Snap...
CVE-2020-3626HIGH7.8Any application can bind to it and exercise the APIs due to no protection for AIDL uimlpaservice in Snapdragon Auto, Sna...
CVE-2020-3613HIGH7.8Double free issue in kernel memory mapping due to lack of memory protection mechanism in Snapdragon Compute, Snapdragon ...
CVE-2020-14960HIGH7.2A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype param...
CVE-2020-14950HIGH8.8aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a modi...
CVE-2020-14933HIGH8.8compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST requ...
CVE-2020-13263HIGH8.8An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13...
CVE-2020-13275HIGH8.1A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later ...
CVE-2020-13274HIGH7.5A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts ...
CVE-2020-13273HIGH7.5A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1
CVE-2020-13272HIGH8.8OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authoriza...
CVE-2020-14930HIGH8.1An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-res...
CVE-2020-14929HIGH7.5Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involvi...
CVE-2020-8184HIGH7.5A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 tha...
CVE-2020-8164HIGH7.5A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker...
CVE-2020-8162HIGH7.5A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStor...
CVE-2020-14459HIGH7.5An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a ...
CVE-2020-14458HIGH7.5An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel...
CVE-2020-14456HIGH7.3An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-contr...
CVE-2020-14453HIGH7.5An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, whi...
CVE-2020-14451HIGH7.5An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local St...
CVE-2020-14450HIGH7.5An issue was discovered in Mattermost Server before 5.22.0. The markdown renderer allows attackers to cause a denial of ...
CVE-2020-14449HIGH7.5An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to thir...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now