2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26603 | MEDIUM | 5.3 | 0.5% | Oct 6, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Sticker Center allows direc... |
| CVE-2020-26602 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), and R(11.0) software.... |
| CVE-2020-26601 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered in DirEncryptService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Pendin... |
| CVE-2020-26600 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) software. Auto Hotspot allows attackers to obtain sensiti... |
| CVE-2020-26599 | MEDIUM | 5.3 | 0.3% | Oct 6, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can ... |
| CVE-2020-26598 | HIGH | 7.5 | 0.3% | Oct 6, 2020 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, and 9.0 software. The Network Management componen... |
| CVE-2020-26597 | HIGH | 7.5 | 0.4% | Oct 6, 2020 | An issue was discovered on LG mobile devices with Android OS 9.0 and 10 software. The Wi-Fi subsystem has incorrect inpu... |
| CVE-2020-16267 | HIGH | 8.8 | 43.3% | Oct 6, 2020 | Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp r... |
| CVE-2020-15927 | HIGH | 8.8 | 40.3% | Oct 6, 2020 | Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp r... |
| CVE-2020-15239 | LOW | 3.5 | 1.5% | Oct 6, 2020 | In xmpp-http-upload before version 0.4.0, when the GET method is attacked, attackers can read files which have a `.data`... |
| CVE-2020-13345 | MEDIUM | 5.4 | 0.9% | Oct 6, 2020 | An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes |
| CVE-2020-13343 | HIGH | 8.8 | 1.5% | Oct 6, 2020 | An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Pro... |
| CVE-2020-13333 | MEDIUM | 4.3 | 2.1% | Oct 6, 2020 | A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a lin... |
| CVE-2020-7740 | HIGH | 8.2 | 2.0% | Oct 6, 2020 | This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to t... |
| CVE-2020-24807 | HIGH | 7.8 | 2.0% | Oct 6, 2020 | The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remot... |
| CVE-2020-1907 | CRITICAL | 9.8 | 1.8% | Oct 6, 2020 | A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, Wha... |
| CVE-2020-1906 | HIGH | 7.8 | 0.3% | Oct 6, 2020 | A buffer overflow in WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 could h... |
| CVE-2020-1905 | LOW | 3.3 | 0.6% | Oct 6, 2020 | Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for ... |
| CVE-2020-1904 | MEDIUM | 5.5 | 1.1% | Oct 6, 2020 | A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have... |
| CVE-2020-1903 | MEDIUM | 5.5 | 0.7% | Oct 6, 2020 | An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for i... |
| CVE-2020-1902 | HIGH | 7.5 | 0.7% | Oct 6, 2020 | A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or Whats... |
| CVE-2020-1901 | MEDIUM | 5.3 | 1.0% | Oct 6, 2020 | Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application... |
| CVE-2020-15215 | MEDIUM | 5.6 | 0.7% | Oct 6, 2020 | Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using b... |
| CVE-2020-15174 | HIGH | 7.5 | 1.3% | Oct 6, 2020 | In Electron before versions 11.0.0-beta.1, 10.0.1, 9.3.0 or 8.5.1 the `will-navigate` event that apps use to prevent nav... |
| CVE-2020-4528 | MEDIUM | 5.5 | 0.3% | Oct 6, 2020 | IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under spe... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now