2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8569MEDIUM6.5Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resour...
CVE-2020-8568MEDIUM6.5Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassP...
CVE-2020-8567MEDIUM6.5Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to...
CVE-2020-8554MEDIUM5Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.exter...
CVE-2020-4969MEDIUM5.9IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, c...
CVE-2020-4968MEDIUM6.5IBM Security Identity Governance and Intelligence 5.2.6 uses weaker than expected cryptographic algorithms that could al...
CVE-2020-4966MEDIUM4.3IBM Security Identity Governance and Intelligence 5.2.6 does not set the secure attribute on authorization tokens or ses...
CVE-2020-4958CRITICAL9.8IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requi...
CVE-2020-26295HIGH7.2OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrat...
CVE-2020-26285HIGH7.2OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vul...
CVE-2020-3691CRITICAL9.8Possible out of bound memory access in audio due to integer underflow while processing modified contents in Snapdragon A...
CVE-2020-3687MEDIUM5.5Local privilege escalation in admin services in Windows environment can occur due to an arbitrary read issue.
CVE-2020-3686CRITICAL9.8Possible memory out of bound issue during music playback when an incorrect bit stream content is copied into array witho...
CVE-2020-3685HIGH7.5Pointer variable which is freed is not cleared can result in memory corruption and leads to denial of service in Snapdra...
CVE-2020-11225CRITICAL9.8Out of bound access in WLAN driver due to lack of validation of array length before copying into array in Snapdragon Aut...
CVE-2020-11217HIGH7.8A possible double free or invalid memory access in audio driver while reading Speaker Protection parameters in Snapdrago...
CVE-2020-11216CRITICAL9.8Buffer over read can happen in video driver when playing clip with atomsize having value UINT32_MAX in Snapdragon Auto, ...
CVE-2020-11215CRITICAL9.1An out of bounds read can happen when processing VSA attribute due to improper minimum required length check in Snapdrag...
CVE-2020-11214HIGH7.5Buffer over-read while processing NDL attribute if attribute length is larger than expected and then FW is treating it a...
CVE-2020-11213CRITICAL9.8Out of bound reads might occur in while processing Service descriptor due to improper validation of length of fields in ...
CVE-2020-11212CRITICAL9.8Out of bounds reads while parsing NAN beacons attributes and OUIs due to improper length of field check in Snapdragon Au...
CVE-2020-11200HIGH7.5Buffer over-read while parsing RPS due to lack of check of input validation on values received from user side. in Snapdr...
CVE-2020-11197CRITICAL9.8Possible integer overflow can occur when stream info update is called when total number of streams detected are zero whi...
CVE-2020-11185HIGH7.8Out of bound issue in WLAN driver while processing vdev responses from firmware due to lack of validation of data receiv...
CVE-2020-11183MEDIUM6.7A process can potentially cause a buffer overflow in the display service allowing privilege escalation by executing code...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now