2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15350CRITICAL9.8RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64_decode() uses an output buffer es...
CVE-2020-15515HIGH8.8The turn extension through 0.3.2 for TYPO3 allows Remote Code Execution.
CVE-2020-15035MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15034MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15033MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15032MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15031MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15030MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15029MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15028MEDIUM5.4NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary ...
CVE-2020-11882MEDIUM6.1The O2 Business application 1.2.0 for Android exposes the canvasm.myo2.SplashActivity activity to other applications. Th...
CVE-2020-15037MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15036MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15584MEDIUM5.5An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can trigger an out-of-bounds access a...
CVE-2020-15583MEDIUM5.5An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. StickerProvider allows dire...
CVE-2020-15582MEDIUM5.5An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 7885 chipsets) software. The Bluetooth...
CVE-2020-15581MEDIUM5.3An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The kernel logging feature ...
CVE-2020-15580MEDIUM5.5An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factor...
CVE-2020-15579HIGH7.5An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factor...
CVE-2020-15578MEDIUM5.5An issue was discovered on Samsung mobile devices with O(8.x) software. FactoryCamera does not properly restrict runtime...
CVE-2020-15577MEDIUM5.5An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Cameralyzer allows attackers to writ...
CVE-2020-15576HIGH7.5SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response.
CVE-2020-15575MEDIUM6.1SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194.
CVE-2020-15574HIGH7.5SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893.
CVE-2020-15573MEDIUM6.1SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now