2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-11072HIGH8.6In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcom...
CVE-2020-11071HIGH8.6SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability where users could experience false-negative validat...
CVE-2020-10067HIGH7.8A malicious userspace application can cause a integer overflow and bypass security checks performed by system call handl...
CVE-2020-10058HIGH7.8Multiple syscalls in the Kscan subsystem perform insufficient argument validation, allowing code executing in userspace ...
CVE-2020-10028HIGH7.8Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr ve...
CVE-2020-10027HIGH7.8An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. Se...
CVE-2020-10024HIGH7.8The arm platform-specific code uses a signed integer comparison when validating system call numbers. An attacker who has...
CVE-2020-10021HIGH7.8Out-of-bounds Write in the USB Mass Storage memoryWrite handler with unaligned Sizes See NCC-ZEP-024, NCC-ZEP-025, NCC-Z...
CVE-2020-10019HIGH7.8USB DFU has a potential buffer overflow where the requested length (wLength) is not checked against the buffer size. Thi...
CVE-2020-9840HIGH7.5In SwiftNIO Extras before 1.4.1, a logic issue was addressed with improved restrictions.
CVE-2020-5837HIGH7.8Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replace...
CVE-2020-5836HIGH7.8Symantec Endpoint Protection, prior to 14.3, can potentially reset the ACLs on a file as a limited user while Symantec E...
CVE-2020-5835HIGH7Symantec Endpoint Protection Manager, prior to 14.3, has a race condition in client remote deployment which may result i...
CVE-2020-12790HIGH7.5In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This lea...
CVE-2020-12785HIGH8.1cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature ...
CVE-2020-12760HIGH8.8An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The Ac...
CVE-2020-12754HIGH7.8An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A crafted application ca...
CVE-2020-12752HIGH7.5An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determi...
CVE-2020-12751HIGH7.8An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) software. The Quram image codec libra...
CVE-2020-12750HIGH7.5An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass Factory Reset Protection (...
CVE-2020-12749HIGH7.8An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The S.LSI Wi-Fi drivers have a...
CVE-2020-12745HIGH7.5An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protectio...
CVE-2020-11866HIGH7.8libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.
CVE-2020-11865HIGH7.8libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.
CVE-2020-11108HIGH8.8The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now