2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25494CRITICAL9.8Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in ou...
CVE-2020-26178MEDIUM5.3In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments wit...
CVE-2020-26177MEDIUM4.3In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not int...
CVE-2020-26176MEDIUM4.3An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /ap...
CVE-2020-26175MEDIUM6.5In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in...
CVE-2020-26174HIGH8.8tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the...
CVE-2020-26173MEDIUM4.3An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download docu...
CVE-2020-26172MEDIUM6.5Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse th...
CVE-2020-26171MEDIUM4.3In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can ...
CVE-2020-35555HIGH7.8An issue was discovered on LG mobile devices with Android OS 10 software. When a dual-screen configuration is supported,...
CVE-2020-35554HIGH7.8An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. There is a WebView SSL erro...
CVE-2020-35553HIGH7.5An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Qualcomm SM8250 chipsets) software. They all...
CVE-2020-35552MEDIUM5.3An issue was discovered in the GPS daemon on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (non-Qualcomm chips...
CVE-2020-35551CRITICAL9.8An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allo...
CVE-2020-35550CRITICAL9.8An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypa...
CVE-2020-35549MEDIUM5.5An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Any application may establi...
CVE-2020-35548MEDIUM5.5An issue was discovered in Finder on Samsung mobile devices with Q(10.0) software. A call to a non-existent provider all...
CVE-2020-35480MEDIUM5.3An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts...
CVE-2020-35479MEDIUM6.1MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in a...
CVE-2020-35478MEDIUM6.1MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw ...
CVE-2020-35477MEDIUM5.3MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpag...
CVE-2020-35475HIGH7.5In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS ...
CVE-2020-35474MEDIUM6.1In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of...
CVE-2020-27640HIGH8.1The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthentica...
CVE-2020-27639HIGH8.1The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an un...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now