2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-0287MEDIUM6.5In libmkvextractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote den...
CVE-2020-0279MEDIUM6.5In the AAC parser, there is a possible out of bounds read due to a missing bounds check. This could lead to remote infor...
CVE-2020-0277HIGH7.8In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission check. This could lea...
CVE-2020-0275HIGH7.8In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access...
CVE-2020-0274MEDIUM5.5In the OMX parser, there is a possible information disclosure due to a returned raw pointer. This could lead to local in...
CVE-2020-0270MEDIUM6.5In tremolo, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information ...
CVE-2020-0267HIGH7.8In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local esc...
CVE-2020-0266HIGH7.8In factory reset protection, there is a possible FRP bypass due to a missing permission check. This could lead to local ...
CVE-2020-0264HIGH8.8In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to remote code ex...
CVE-2020-0130HIGH7.8In screencap, there is a possible command injection due to improper input validation. This could lead to local escalatio...
CVE-2020-0125MEDIUM5.5In mediadrm, there is a possible out of bounds read due to a missing bounds check. This could lead to local information ...
CVE-2020-15183MEDIUM4.8SoyCMS 3.0.2 and earlier is affected by Reflected Cross-Site Scripting (XSS) which leads to Remote Code Execution (RCE) ...
CVE-2020-15182CRITICAL9.6The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). T...
CVE-2020-13260MEDIUM6.1A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated ...
CVE-2020-25216CRITICAL9.8yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction w...
CVE-2020-25215CRITICAL9.8yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document.
CVE-2020-24750HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-0435Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-14615. Reason: This candidate is a duplicate of ...
CVE-2020-0434HIGH7.8In Pixel's use of the Catpipe library, there is possible memory corruption due to a use after free. This could lead to l...
CVE-2020-0433HIGH7.8In blk_mq_queue_tag_busy_iter of blk-mq-tag.c, there is a possible use after free due to improper locking. This could le...
CVE-2020-0432HIGH7.8In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to ...
CVE-2020-0431MEDIUM6.7In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to ...
CVE-2020-0430HIGH7.8In skb_headlen of /include/linux/skbuff.h, there is a possible out of bounds read due to memory corruption. This could l...
CVE-2020-0429MEDIUM6.7In l2tp_session_delete and related functions of l2tp_core.c, there is possible memory corruption due to a use after free...
CVE-2020-0428MEDIUM6.4In CamX code, there is a possible use after free due to a race condition. This could lead to local escalation of privile...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now