2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35263 | CRITICAL | 9.8 | 2.5% | Jan 26, 2021 | EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbi... |
| CVE-2020-28998 | CRITICAL | 9.8 | 2.8% | Jan 26, 2021 | An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the Telnet service that all... |
| CVE-2020-28221 | CRITICAL | 9.8 | 1.8% | Jan 26, 2021 | A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (ver... |
| CVE-2020-27583 | CRITICAL | 9.8 | 3.7% | Jan 26, 2021 | IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unau... |
| CVE-2020-27540 | CRITICAL | 9.8 | 0.8% | Jan 26, 2021 | Bash injection vulnerability and bypass of signature verification in Rostelecom CS-C2SHW 5.0.082.1. The camera reads fir... |
| CVE-2020-27539 | CRITICAL | 9.8 | 1.3% | Jan 26, 2021 | Heap overflow with full parsing of HTTP respose in Rostelecom CS-C2SHW 5.0.082.1. AgentUpdater service has a self-writte... |
| CVE-2020-23448 | CRITICAL | 9.8 | 1.6% | Jan 26, 2021 | newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginIntercep... |
| CVE-2020-23262 | CRITICAL | 9.8 | 1.1% | Jan 26, 2021 | An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in thro... |
| CVE-2020-20269 | CRITICAL | 9.8 | 4.7% | Jan 26, 2021 | A specially crafted Markdown document could cause the execution of malicious JavaScript code in Caret Editor before 4.0.... |
| CVE-2020-8570 | CRITICAL | 9.1 | 3.5% | Jan 21, 2021 | Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the curr... |
| CVE-2020-4958 | CRITICAL | 9.8 | 1.7% | Jan 21, 2021 | IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requi... |
| CVE-2020-3691 | CRITICAL | 9.8 | 1.1% | Jan 21, 2021 | Possible out of bound memory access in audio due to integer underflow while processing modified contents in Snapdragon A... |
| CVE-2020-3686 | CRITICAL | 9.8 | 1.2% | Jan 21, 2021 | Possible memory out of bound issue during music playback when an incorrect bit stream content is copied into array witho... |
| CVE-2020-11225 | CRITICAL | 9.8 | 1.1% | Jan 21, 2021 | Out of bound access in WLAN driver due to lack of validation of array length before copying into array in Snapdragon Aut... |
| CVE-2020-11216 | CRITICAL | 9.8 | 0.9% | Jan 21, 2021 | Buffer over read can happen in video driver when playing clip with atomsize having value UINT32_MAX in Snapdragon Auto, ... |
| CVE-2020-11215 | CRITICAL | 9.1 | 0.9% | Jan 21, 2021 | An out of bounds read can happen when processing VSA attribute due to improper minimum required length check in Snapdrag... |
| CVE-2020-11213 | CRITICAL | 9.8 | 0.9% | Jan 21, 2021 | Out of bound reads might occur in while processing Service descriptor due to improper validation of length of fields in ... |
| CVE-2020-11212 | CRITICAL | 9.8 | 0.9% | Jan 21, 2021 | Out of bounds reads while parsing NAN beacons attributes and OUIs due to improper length of field check in Snapdragon Au... |
| CVE-2020-11197 | CRITICAL | 9.8 | 0.9% | Jan 21, 2021 | Possible integer overflow can occur when stream info update is called when total number of streams detected are zero whi... |
| CVE-2020-11167 | CRITICAL | 9.8 | 1.2% | Jan 21, 2021 | Memory corruption while calculating L2CAP packet length in reassembly logic when remote sends more data than expected in... |
| CVE-2020-11144 | CRITICAL | 9.1 | 0.9% | Jan 21, 2021 | Buffer over-read while UE process invalid DL ROHC packet for decompression due to lack of check of size of compresses pa... |
| CVE-2020-11143 | CRITICAL | 9.8 | 1.1% | Jan 21, 2021 | Out of bound memory access during music playback with modified content due to copying data without checking destination ... |
| CVE-2020-11140 | CRITICAL | 9.8 | 1.1% | Jan 21, 2021 | Out of bound memory access during music playback with ALAC modified content due to improper validation in Snapdragon Aut... |
| CVE-2020-11138 | CRITICAL | 9.8 | 1.1% | Jan 21, 2021 | Uninitialized pointers accessed during music play back with incorrect bit stream due to an uninitialized heap memory res... |
| CVE-2020-11137 | CRITICAL | 9.8 | 1.1% | Jan 21, 2021 | Integer multiplication overflow resulting in lower buffer size allocation than expected causes memory access out of boun... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now