2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-0427MEDIUM5.5In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local in...
CVE-2020-0403MEDIUM6.7In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This c...
CVE-2020-0387HIGH7.8In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. Th...
CVE-2020-25729MEDIUM6.1ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.
CVE-2020-25489CRITICAL9.8A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploi...
CVE-2020-24753CRITICAL9.8A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow a...
CVE-2020-13169CRITICAL9Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and p...
CVE-2020-25728HIGH8.8The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malici...
CVE-2020-25727HIGH7.5The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to in...
CVE-2020-25490HIGH7.3Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote att...
CVE-2020-24046HIGH7.2A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell,...
CVE-2020-24045HIGH7.2A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell,...
CVE-2020-11804HIGH8.8An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page ma...
CVE-2020-11803HIGH8.8An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with th...
CVE-2020-11700MEDIUM6.5An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x....
CVE-2020-11699HIGH8.8An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php woul...
CVE-2020-11698CRITICAL9.8An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp...
CVE-2020-0407MEDIUM4.4In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption h...
CVE-2020-0404MEDIUM5.5In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This...
CVE-2020-0401HIGH7.8In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local ...
CVE-2020-0399MEDIUM5.5In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an un...
CVE-2020-0397MEDIUM5.5In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe Pen...
CVE-2020-0396MEDIUM5.5In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to...
CVE-2020-0395MEDIUM5.5In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due to an unsafe Pending...
CVE-2020-0394HIGH7.8In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now