2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3663CRITICAL9.8Buffer over-write may occur during fetching track decoder specific information if cb size exceeds buffer size in Snapdra...
CVE-2020-3662CRITICAL9.8Buffer overflow can occur while parsing eac3 header while playing the clip which is nonstandard in Snapdragon Auto, Snap...
CVE-2020-3661CRITICAL9.8Buffer overflow will happen while parsing mp4 clip with corrupted sample atoms values which exceeds MAX_UINT32 range due...
CVE-2020-3660CRITICAL9.8Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto,...
CVE-2020-3658CRITICAL9.1Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto,...
CVE-2020-3642HIGH7.8Use after free issue in camera applications when used randomly over multiple operations due to pointer not set to NULL a...
CVE-2020-3635HIGH7.8Stack based overflow If the maximum number of arguments allowed per request in perflock exceeds in Snapdragon Auto, Snap...
CVE-2020-3628CRITICAL9.8Improper access due to socket opened by the logging application without specifying localhost address in Snapdragon Consu...
CVE-2020-3626HIGH7.8Any application can bind to it and exercise the APIs due to no protection for AIDL uimlpaservice in Snapdragon Auto, Sna...
CVE-2020-3614CRITICAL9.8Possible buffer overflow while copying the frame to local buffer due to lack of check of length before copying in Snapdr...
CVE-2020-3613HIGH7.8Double free issue in kernel memory mapping due to lack of memory protection mechanism in Snapdragon Compute, Snapdragon ...
CVE-2020-14962MEDIUM5.4Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inj...
CVE-2020-14961MEDIUM5.3Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.
CVE-2020-14960HIGH7.2A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype param...
CVE-2020-14959MEDIUM5.4Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject a...
CVE-2020-14467Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-14958MEDIUM6.5In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.
CVE-2020-14954MEDIUM5.9Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When...
CVE-2020-14950HIGH8.8aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a modi...
CVE-2020-14942CRITICAL9.8Tendenci 12.0.10 allows unrestricted deserialization in apps\helpdesk\views\staff.py.
CVE-2020-14933HIGH8.8compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST requ...
CVE-2020-14932CRITICAL9.8compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET reques...
CVE-2020-13264MEDIUM5.3Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view...
CVE-2020-13263HIGH8.8An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13...
CVE-2020-13261LOW2.7Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amaz...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now