2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-10068MEDIUM6.5In the Zephyr project Bluetooth subsystem, certain duplicate and back-to-back packets can cause incorrect behavior, resu...
CVE-2020-8555MEDIUM6.3The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version ...
CVE-2020-9074MEDIUM5.3Huawei Smartphones HONOR 20 PRO;Honor View 20;HONOR 20 have an improper handling of exceptional condition Vulnerability....
CVE-2020-1883MEDIUM4.9Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with high privileges exp...
CVE-2020-12849MEDIUM5.4Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user r...
CVE-2020-12848MEDIUM5.4In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden share...
CVE-2020-13843MEDIUM5.5An issue was discovered on LG mobile devices with Android OS software before 2020-06-01. Local users can cause a denial ...
CVE-2020-12853MEDIUM6.1Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially maliciou...
CVE-2020-12852MEDIUM6.8The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key ...
CVE-2020-11682MEDIUM6.5Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by th...
CVE-2020-11680MEDIUM6.5Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fail...
CVE-2020-10702MEDIUM5.5A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in versi...
CVE-2020-9462MEDIUM4.3An issue was discovered in all Athom Homey and Homey Pro devices up to the current version 4.2.0. An attacker within RF ...
CVE-2020-13800MEDIUM6ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index val...
CVE-2020-13791MEDIUM5.5hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end...
CVE-2020-13765MEDIUM5.6rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which all...
CVE-2020-13827MEDIUM6.1phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.
CVE-2020-4191MEDIUM4.4IBM Security Guardium 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hi...
CVE-2020-4183MEDIUM6.1IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2020-6640MEDIUM5.4An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated...
CVE-2020-7030MEDIUM5.5A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may pot...
CVE-2020-6504MEDIUM4.3Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to by...
CVE-2020-6503MEDIUM6.5Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtai...
CVE-2020-6502MEDIUM6.5Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof securi...
CVE-2020-6501MEDIUM6.5Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass conten...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now