2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0287 | MEDIUM | 6.5 | 0.6% | Sep 17, 2020 | In libmkvextractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote den... |
| CVE-2020-0279 | MEDIUM | 6.5 | 1.0% | Sep 17, 2020 | In the AAC parser, there is a possible out of bounds read due to a missing bounds check. This could lead to remote infor... |
| CVE-2020-0277 | HIGH | 7.8 | 0.1% | Sep 17, 2020 | In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission check. This could lea... |
| CVE-2020-0275 | HIGH | 7.8 | 0.2% | Sep 17, 2020 | In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access... |
| CVE-2020-0274 | MEDIUM | 5.5 | 0.1% | Sep 17, 2020 | In the OMX parser, there is a possible information disclosure due to a returned raw pointer. This could lead to local in... |
| CVE-2020-0270 | MEDIUM | 6.5 | 0.8% | Sep 17, 2020 | In tremolo, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information ... |
| CVE-2020-0267 | HIGH | 7.8 | 0.5% | Sep 17, 2020 | In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local esc... |
| CVE-2020-0266 | HIGH | 7.8 | 0.2% | Sep 17, 2020 | In factory reset protection, there is a possible FRP bypass due to a missing permission check. This could lead to local ... |
| CVE-2020-0264 | HIGH | 8.8 | 0.7% | Sep 17, 2020 | In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to remote code ex... |
| CVE-2020-0130 | HIGH | 7.8 | 0.4% | Sep 17, 2020 | In screencap, there is a possible command injection due to improper input validation. This could lead to local escalatio... |
| CVE-2020-0125 | MEDIUM | 5.5 | 0.1% | Sep 17, 2020 | In mediadrm, there is a possible out of bounds read due to a missing bounds check. This could lead to local information ... |
| CVE-2020-15183 | MEDIUM | 4.8 | 1.7% | Sep 17, 2020 | SoyCMS 3.0.2 and earlier is affected by Reflected Cross-Site Scripting (XSS) which leads to Remote Code Execution (RCE) ... |
| CVE-2020-15182 | CRITICAL | 9.6 | 1.2% | Sep 17, 2020 | The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). T... |
| CVE-2020-13260 | MEDIUM | 6.1 | 2.0% | Sep 17, 2020 | A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated ... |
| CVE-2020-25216 | CRITICAL | 9.8 | 2.4% | Sep 17, 2020 | yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction w... |
| CVE-2020-25215 | CRITICAL | 9.8 | 1.2% | Sep 17, 2020 | yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document. |
| CVE-2020-24750 | HIGH | 8.1 | 7.3% | Sep 17, 2020 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-0435 | — | — | — | Sep 17, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-14615. Reason: This candidate is a duplicate of ... |
| CVE-2020-0434 | HIGH | 7.8 | 0.2% | Sep 17, 2020 | In Pixel's use of the Catpipe library, there is possible memory corruption due to a use after free. This could lead to l... |
| CVE-2020-0433 | HIGH | 7.8 | 0.2% | Sep 17, 2020 | In blk_mq_queue_tag_busy_iter of blk-mq-tag.c, there is a possible use after free due to improper locking. This could le... |
| CVE-2020-0432 | HIGH | 7.8 | 0.2% | Sep 17, 2020 | In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to ... |
| CVE-2020-0431 | MEDIUM | 6.7 | 0.2% | Sep 17, 2020 | In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to ... |
| CVE-2020-0430 | HIGH | 7.8 | 0.2% | Sep 17, 2020 | In skb_headlen of /include/linux/skbuff.h, there is a possible out of bounds read due to memory corruption. This could l... |
| CVE-2020-0429 | MEDIUM | 6.7 | 0.2% | Sep 17, 2020 | In l2tp_session_delete and related functions of l2tp_core.c, there is possible memory corruption due to a use after free... |
| CVE-2020-0428 | MEDIUM | 6.4 | 0.1% | Sep 17, 2020 | In CamX code, there is a possible use after free due to a race condition. This could lead to local escalation of privile... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now