2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25494 | CRITICAL | 9.8 | 39.2% | Dec 18, 2020 | Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in ou... |
| CVE-2020-26178 | MEDIUM | 5.3 | 0.9% | Dec 18, 2020 | In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments wit... |
| CVE-2020-26177 | MEDIUM | 4.3 | 0.6% | Dec 18, 2020 | In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not int... |
| CVE-2020-26176 | MEDIUM | 4.3 | 0.7% | Dec 18, 2020 | An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /ap... |
| CVE-2020-26175 | MEDIUM | 6.5 | 0.7% | Dec 18, 2020 | In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in... |
| CVE-2020-26174 | HIGH | 8.8 | 1.2% | Dec 18, 2020 | tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the... |
| CVE-2020-26173 | MEDIUM | 4.3 | 0.7% | Dec 18, 2020 | An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download docu... |
| CVE-2020-26172 | MEDIUM | 6.5 | 0.7% | Dec 18, 2020 | Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse th... |
| CVE-2020-26171 | MEDIUM | 4.3 | 0.6% | Dec 18, 2020 | In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can ... |
| CVE-2020-35555 | HIGH | 7.8 | 0.1% | Dec 18, 2020 | An issue was discovered on LG mobile devices with Android OS 10 software. When a dual-screen configuration is supported,... |
| CVE-2020-35554 | HIGH | 7.8 | 0.1% | Dec 18, 2020 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. There is a WebView SSL erro... |
| CVE-2020-35553 | HIGH | 7.5 | 0.4% | Dec 18, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Qualcomm SM8250 chipsets) software. They all... |
| CVE-2020-35552 | MEDIUM | 5.3 | 0.3% | Dec 18, 2020 | An issue was discovered in the GPS daemon on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (non-Qualcomm chips... |
| CVE-2020-35551 | CRITICAL | 9.8 | 0.4% | Dec 18, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allo... |
| CVE-2020-35550 | CRITICAL | 9.8 | 0.6% | Dec 18, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypa... |
| CVE-2020-35549 | MEDIUM | 5.5 | 0.1% | Dec 18, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Any application may establi... |
| CVE-2020-35548 | MEDIUM | 5.5 | 0.1% | Dec 18, 2020 | An issue was discovered in Finder on Samsung mobile devices with Q(10.0) software. A call to a non-existent provider all... |
| CVE-2020-35480 | MEDIUM | 5.3 | 1.5% | Dec 18, 2020 | An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts... |
| CVE-2020-35479 | MEDIUM | 6.1 | 1.5% | Dec 18, 2020 | MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in a... |
| CVE-2020-35478 | MEDIUM | 6.1 | 1.4% | Dec 18, 2020 | MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw ... |
| CVE-2020-35477 | MEDIUM | 5.3 | 1.5% | Dec 18, 2020 | MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpag... |
| CVE-2020-35475 | HIGH | 7.5 | 1.6% | Dec 18, 2020 | In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS ... |
| CVE-2020-35474 | MEDIUM | 6.1 | 1.0% | Dec 18, 2020 | In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of... |
| CVE-2020-27640 | HIGH | 8.1 | 0.5% | Dec 18, 2020 | The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthentica... |
| CVE-2020-27639 | HIGH | 8.1 | 0.5% | Dec 18, 2020 | The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an un... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now