2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15771HIGH7.5An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission ...
CVE-2020-15770MEDIUM5.5An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local...
CVE-2020-15769MEDIUM6.1An issue was discovered in Gradle Enterprise 2020.2 - 2020.2.4. An XSS issue exists via the request URL.
CVE-2020-15768HIGH7.5An issue was discovered in Gradle Enterprise 2017.3 - 2020.2.4 and Gradle Enterprise Build Cache Node 1.0 - 9.2. Unrestr...
CVE-2020-15767MEDIUM5.3An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not...
CVE-2020-5629MEDIUM6.5UNIQLO App for Android versions 7.3.3 and earlier allows remote attackers to lead a user to access an arbitrary website ...
CVE-2020-5628MEDIUM6.5UNIQLO App for Android versions 7.3.3 and earlier allows remote attackers to lead a user to access an arbitrary website ...
CVE-2020-5606MEDIUM6.1Cross-site scripting vulnerability in WHR-G54S firmware 1.43 and earlier allows remote attackers to inject arbitrary scr...
CVE-2020-5605MEDIUM4.3Directory traversal vulnerability in WHR-G54S firmware 1.43 and earlier allows an attacker to access sensitive informati...
CVE-2020-25756CRITICAL9.8A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of boun...
CVE-2020-25751HIGH8.8The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=c...
CVE-2020-25750HIGH7.5An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is ...
CVE-2020-25744HIGH8.1SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could ...
CVE-2020-25735MEDIUM6.1webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement...
CVE-2020-25734MEDIUM5.3webTareas through 2.1 allows files/Default/ Directory Listing.
CVE-2020-25733HIGH7.5webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
CVE-2020-15187MEDIUM4.7In Helm before versions 2.16.11 and 3.3.2, a Helm plugin can contain duplicates of the same entry, with the last one alw...
CVE-2020-15186LOW2.7In Helm before versions 2.16.11 and 3.3.2 plugin names are not sanitized properly. As a result, a malicious plugin autho...
CVE-2020-15185LOW2.7In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one...
CVE-2020-15184LOW2.7In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sa...
CVE-2020-0426MEDIUM5.5In SyncManager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local informati...
CVE-2020-0425MEDIUM5.5There is a possible way to view notifications even when the "Lockdown" feature is on. This could lead to local informati...
CVE-2020-0406HIGH7.8In libmpeg2dec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalati...
CVE-2020-0375HIGH7.8In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalati...
CVE-2020-0374HIGH7.8In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of pri...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now