2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35456 | MEDIUM | 5.5 | 0.5% | Mar 17, 2021 | The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and m... |
| CVE-2020-35454 | MEDIUM | 6.8 | 0.2% | Mar 17, 2021 | The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an ... |
| CVE-2020-11308 | MEDIUM | 6.8 | 0.2% | Mar 17, 2021 | Buffer overflow occurs when trying to convert ASCII string to Unicode string if the actual size is more than required in... |
| CVE-2020-11305 | MEDIUM | 6.8 | 0.2% | Mar 17, 2021 | Integer overflow in boot due to improper length check on arguments received in Snapdragon Consumer IOT, Snapdragon Indus... |
| CVE-2020-11230 | MEDIUM | 6.4 | 0.1% | Mar 17, 2021 | Potential arbitrary memory corruption when the qseecom driver updates ion physical addresses in the buffer as it exposes... |
| CVE-2020-11221 | MEDIUM | 5.5 | 0.2% | Mar 17, 2021 | Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due ... |
| CVE-2020-11220 | MEDIUM | 6.4 | 0.1% | Mar 17, 2021 | While processing storage SCM commands there is a time of check or time of use window where a pointer used could be inval... |
| CVE-2020-11199 | MEDIUM | 5.5 | 0.2% | Mar 17, 2021 | HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information e... |
| CVE-2020-11186 | MEDIUM | 5.5 | 0.2% | Mar 17, 2021 | Modem will enter into busy mode in an infinite loop while parsing histogram dimension due to improper validation of inpu... |
| CVE-2020-4891 | MEDIUM | 5.5 | 0.2% | Mar 16, 2021 | IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could... |
| CVE-2020-4890 | MEDIUM | 4.4 | 0.2% | Mar 16, 2021 | IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user with a valid role to the RES... |
| CVE-2020-4851 | MEDIUM | 5.5 | 0.3% | Mar 16, 2021 | IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which co... |
| CVE-2020-1926 | MEDIUM | 5.9 | 2.5% | Mar 16, 2021 | Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing ... |
| CVE-2020-27290 | MEDIUM | 4.3 | 0.3% | Mar 15, 2021 | In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilato... |
| CVE-2020-27282 | MEDIUM | 4.3 | 0.3% | Mar 15, 2021 | In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in the ventilator allows... |
| CVE-2020-27278 | MEDIUM | 5.2 | 0.3% | Mar 15, 2021 | In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, hard-coded credentials in the ventilator allow attackers... |
| CVE-2020-29556 | MEDIUM | 5.5 | 1.0% | Mar 15, 2021 | The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files ... |
| CVE-2020-24982 | MEDIUM | 4.3 | 0.4% | Mar 15, 2021 | An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick... |
| CVE-2020-28387 | MEDIUM | 5.5 | 0.9% | Mar 15, 2021 | A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < ... |
| CVE-2020-25236 | MEDIUM | 5.5 | 0.3% | Mar 15, 2021 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0... |
| CVE-2020-14989 | MEDIUM | 6.5 | 0.6% | Mar 11, 2021 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker use... |
| CVE-2020-14988 | MEDIUM | 5.4 | 0.6% | Mar 11, 2021 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page vi... |
| CVE-2020-4976 | MEDIUM | 4.4 | 0.3% | Mar 11, 2021 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us... |
| CVE-2020-15260 | MEDIUM | 6.8 | 1.0% | Mar 10, 2021 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto... |
| CVE-2020-35233 | MEDIUM | 6.5 | 0.6% | Mar 10, 2021 | The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now