2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-0100MEDIUM5.5In onTransact of IHDCP.cpp, there is a possible out of bounds read due to incorrect error handling. This could lead to l...
CVE-2020-0093MEDIUM5In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This ...
CVE-2020-0092MEDIUM5In setHideSensitive of NotificationStackScrollLayout.java, there is a possible disclosure of sensitive notification cont...
CVE-2020-0091MEDIUM5.5In mnld, an incorrect configuration in driver_cfg of mnld for meta factory mode.Product: AndroidVersions: Android SoCAnd...
CVE-2020-0090MEDIUM5.5An improper authorization in the receiver component of Email.Product: AndroidVersions: Android SoCAndroid ID: A-14981304...
CVE-2020-0065MEDIUM5.5An improper authorization in the receiver component of the Android Suite Daemon.Product: AndroidVersions: Android SoCAnd...
CVE-2020-0064MEDIUM5.5An improper authorization while processing the provisioning data.Product: AndroidVersions: Android SoCAndroid ID: A-1498...
CVE-2020-12875MEDIUM6.3Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain un...
CVE-2020-5408MEDIUM6.5Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4....
CVE-2020-12677MEDIUM6.1An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately s...
CVE-2020-1960MEDIUM4.7A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 t...
CVE-2020-1941MEDIUM6.1In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a q...
CVE-2020-4365MEDIUM4.3IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted reques...
CVE-2020-4299MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user throug...
CVE-2020-4259MEDIUM6.5IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information ...
CVE-2020-1945MEDIUM6.3Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system propert...
CVE-2020-12717MEDIUM6.5The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere ...
CVE-2020-5575MEDIUM6.1Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), M...
CVE-2020-5574MEDIUM5.3HTML attribute value injection vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable ...
CVE-2020-5409MEDIUM6.1Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unau...
CVE-2020-11065MEDIUM5.4In TYPO3 CMS greater than or equal to 9.5.12 and less than 9.5.17, and greater than or equal to 10.2.0 and less than 10....
CVE-2020-11064MEDIUM5.4In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4....
CVE-2020-2017MEDIUM6.1A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces. A remote attacke...
CVE-2020-2005MEDIUM6.1A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalPro...
CVE-2020-2004MEDIUM5.5Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now