2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-0254HIGH7.5There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID:...
CVE-2020-0253CRITICAL9.8There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-1526473...
CVE-2020-0252CRITICAL9.8There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-1522368...
CVE-2020-0251HIGH7.5There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID:...
CVE-2020-0250MEDIUM5.5In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to ...
CVE-2020-0249MEDIUM5.5In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. T...
CVE-2020-0248MEDIUM5.5In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. T...
CVE-2020-0247MEDIUM5.5In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an uncaught exception. This...
CVE-2020-0243HIGH7.8In clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper locking. This could lead...
CVE-2020-0242HIGH7.8In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local esc...
CVE-2020-0241HIGH7.8In NuPlayerStreamListener of NuPlayerStreamListener.cpp, there is possible memory corruption due to a double free. This ...
CVE-2020-0240HIGH8.8In NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer overflow. This could lea...
CVE-2020-0239MEDIUM5.5In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to...
CVE-2020-0238HIGH7In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race cond...
CVE-2020-0108HIGH7.8In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncau...
CVE-2020-9404HIGH7.1In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in an insecure manner, and may be modified by a...
CVE-2020-9403MEDIUM5.5In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in a recoverable format, and may be retrieved b...
CVE-2020-9244MEDIUM6.8HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than ...
CVE-2020-8918HIGH7.1An improperly initialized 'migrationAuth' value in Google's go-tpm TPM1.2 library versions prior to 0.3.0 can lead an ea...
CVE-2020-13179MEDIUM5.5Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 ar...
CVE-2020-11976HIGH7.5By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker...
CVE-2020-15071MEDIUM6.1content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.
CVE-2020-14979HIGH7.8The WinRing0.sys and WinRing0x64.sys drivers 1.2.0 in EVGA Precision X1 through 1.0.6 allow local users, including low i...
CVE-2020-13178MEDIUM6.7A function in the Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to version 20.04.1 does...
CVE-2020-13177HIGH7.8The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04....

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now