2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0427 | MEDIUM | 5.5 | 0.5% | Sep 17, 2020 | In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local in... |
| CVE-2020-0403 | MEDIUM | 6.7 | 0.2% | Sep 17, 2020 | In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This c... |
| CVE-2020-0387 | HIGH | 7.8 | 0.5% | Sep 17, 2020 | In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. Th... |
| CVE-2020-25729 | MEDIUM | 6.1 | 1.2% | Sep 17, 2020 | ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php. |
| CVE-2020-25489 | CRITICAL | 9.8 | 2.5% | Sep 17, 2020 | A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploi... |
| CVE-2020-24753 | CRITICAL | 9.8 | 2.6% | Sep 17, 2020 | A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow a... |
| CVE-2020-13169 | CRITICAL | 9 | 2.2% | Sep 17, 2020 | Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and p... |
| CVE-2020-25728 | HIGH | 8.8 | 1.0% | Sep 17, 2020 | The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malici... |
| CVE-2020-25727 | HIGH | 7.5 | 0.9% | Sep 17, 2020 | The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to in... |
| CVE-2020-25490 | HIGH | 7.3 | 1.2% | Sep 17, 2020 | Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote att... |
| CVE-2020-24046 | HIGH | 7.2 | 3.4% | Sep 17, 2020 | A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell,... |
| CVE-2020-24045 | HIGH | 7.2 | 1.6% | Sep 17, 2020 | A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell,... |
| CVE-2020-11804 | HIGH | 8.8 | 7.1% | Sep 17, 2020 | An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page ma... |
| CVE-2020-11803 | HIGH | 8.8 | 7.5% | Sep 17, 2020 | An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with th... |
| CVE-2020-11700 | MEDIUM | 6.5 | 7.1% | Sep 17, 2020 | An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.... |
| CVE-2020-11699 | HIGH | 8.8 | 9.6% | Sep 17, 2020 | An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php woul... |
| CVE-2020-11698 | CRITICAL | 9.8 | 73.7% | Sep 17, 2020 | An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp... |
| CVE-2020-0407 | MEDIUM | 4.4 | 0.1% | Sep 17, 2020 | In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption h... |
| CVE-2020-0404 | MEDIUM | 5.5 | 0.2% | Sep 17, 2020 | In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This... |
| CVE-2020-0401 | HIGH | 7.8 | 0.3% | Sep 17, 2020 | In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local ... |
| CVE-2020-0399 | MEDIUM | 5.5 | 0.2% | Sep 17, 2020 | In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an un... |
| CVE-2020-0397 | MEDIUM | 5.5 | 0.2% | Sep 17, 2020 | In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe Pen... |
| CVE-2020-0396 | MEDIUM | 5.5 | 0.2% | Sep 17, 2020 | In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to... |
| CVE-2020-0395 | MEDIUM | 5.5 | 0.2% | Sep 17, 2020 | In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due to an unsafe Pending... |
| CVE-2020-0394 | HIGH | 7.8 | 0.3% | Sep 17, 2020 | In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now