2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26603MEDIUM5.3An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Sticker Center allows direc...
CVE-2020-26602HIGH7.5An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), and R(11.0) software....
CVE-2020-26601HIGH7.5An issue was discovered in DirEncryptService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Pendin...
CVE-2020-26600HIGH7.5An issue was discovered on Samsung mobile devices with Q(10.0) software. Auto Hotspot allows attackers to obtain sensiti...
CVE-2020-26599MEDIUM5.3An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can ...
CVE-2020-26598HIGH7.5An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, and 9.0 software. The Network Management componen...
CVE-2020-26597HIGH7.5An issue was discovered on LG mobile devices with Android OS 9.0 and 10 software. The Wi-Fi subsystem has incorrect inpu...
CVE-2020-16267HIGH8.8Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp r...
CVE-2020-15927HIGH8.8Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp r...
CVE-2020-15239LOW3.5In xmpp-http-upload before version 0.4.0, when the GET method is attacked, attackers can read files which have a `.data`...
CVE-2020-13345MEDIUM5.4An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes
CVE-2020-13343HIGH8.8An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Pro...
CVE-2020-13333MEDIUM4.3A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a lin...
CVE-2020-7740HIGH8.2This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to t...
CVE-2020-24807HIGH7.8The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remot...
CVE-2020-1907CRITICAL9.8A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, Wha...
CVE-2020-1906HIGH7.8A buffer overflow in WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 could h...
CVE-2020-1905LOW3.3Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for ...
CVE-2020-1904MEDIUM5.5A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have...
CVE-2020-1903MEDIUM5.5An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for i...
CVE-2020-1902HIGH7.5A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or Whats...
CVE-2020-1901MEDIUM5.3Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application...
CVE-2020-15215MEDIUM5.6Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using b...
CVE-2020-15174HIGH7.5In Electron before versions 11.0.0-beta.1, 10.0.1, 9.3.0 or 8.5.1 the `will-navigate` event that apps use to prevent nav...
CVE-2020-4528MEDIUM5.5IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under spe...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now