2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9256MEDIUM6.5Huawei Mate 30 Pro smartphones with versions earlier than 10.1.0.150(C00E136R5P3) have an improper authorization vulnera...
CVE-2020-9101MEDIUM6.5There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets wit...
CVE-2020-9259MEDIUM6.5Huawei Honor V30 smartphones with versions earlier than 10.1.0.212(C00E210R5P1) have an improper authentication vulnerab...
CVE-2020-9257HIGH8.8HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C...
CVE-2020-9255MEDIUM5.5Huawei Honor 10 smartphones with versions earlier than 10.0.0.178(C00E178R1P4) have a denial of service vulnerability. C...
CVE-2020-9254HIGH7.8HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C...
CVE-2020-9252LOW2.3HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R...
CVE-2020-9227MEDIUM5.5Huawei Smart Phones Moana-AL00B with versions earlier than 10.1.0.166 have a missing initialization of resource vulnerab...
CVE-2020-9102LOW3.3There is a information leak vulnerability in some Huawei products, and it could allow a local attacker to get informatio...
CVE-2020-7818HIGH7.8DaviewIndy 8.98.9 and earlier has a Heap-based overflow vulnerability, triggered when the user opens a malformed PDF fil...
CVE-2020-7206CRITICAL9.8HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.
CVE-2020-5769MEDIUM5.4Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.02 allows a remote, authenticated attacker to conduc...
CVE-2020-5768MEDIUM4.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & News...
CVE-2020-5767MEDIUM6.5Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attack...
CVE-2020-10605HIGH7.5Grundfos CIM 500 before v06.16.00 responds to unauthenticated requests for password storage files.
CVE-2020-5759CRITICAL9.8Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authen...
CVE-2020-5758HIGH8.8Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authe...
CVE-2020-5757CRITICAL9.8Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authe...
CVE-2020-5756HIGH8.8Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab ...
CVE-2020-4104MEDIUM5.4HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can us...
CVE-2020-15110HIGH8.1In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant ...
CVE-2020-15108HIGH7.1In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1.
CVE-2020-0231CRITICAL9.8There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid I...
CVE-2020-0230CRITICAL9.8There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid I...
CVE-2020-0228HIGH7.5There is an improper configuration of recorder related service. Product: AndroidVersions: Android SoCAndroid ID: A-15633...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now