2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-0041HIGH7.8In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could ...
CVE-2020-0039HIGH7.5In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible read of uninitialized data due to a missing bounds check. Thi...
CVE-2020-0038HIGH7.5In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible read of uninitialized data due to a missing bounds check. Thi...
CVE-2020-0037HIGH7.5In rw_i93_sm_set_read_only of rw_i93.cc, there is a possible out of bounds read due to a missing bounds check. This coul...
CVE-2020-0036HIGH7.8In hasPermissions of PermissionMonitor.java, there is a possible access to restricted permissions due to a permissions b...
CVE-2020-0034HIGH7.5In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This coul...
CVE-2020-0033HIGH7.8In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to stale pointer. This could l...
CVE-2020-0032HIGH8.8In ih264d_release_display_bufs of ih264d_utils.c, there is a possible out of bounds write due to a heap buffer overflow....
CVE-2020-5259HIGH8.6In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution ...
CVE-2020-5258HIGH7.7In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollutio...
CVE-2020-5254HIGH8.1In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited. NetHack 3.6.6 resolves ...
CVE-2020-5342HIGH7.8Dell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability. A locally authe...
CVE-2020-10248HIGH7.5BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwords via a direct request to val_users.php3.
CVE-2020-10244HIGH7.5JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
CVE-2020-10190HIGH8.8An issue was discovered in MunkiReport before 5.3.0. An authenticated user could achieve SQL Injection in app/models/tab...
CVE-2020-8987HIGH7.4Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate...
CVE-2020-5256HIGH8.8BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, ...
CVE-2020-2159HIGH8.8Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands...
CVE-2020-2158HIGH8.8Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary typ...
CVE-2020-2146HIGH7.4Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabl...
CVE-2020-2144HIGH7.1Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2138HIGH7.1Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks...
CVE-2020-2135HIGH8.8Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls...
CVE-2020-2134HIGH8.8Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor ...
CVE-2020-1737HIGH7.8A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function f...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now