2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-35456MEDIUM5.5The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and m...
CVE-2020-35454MEDIUM6.8The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an ...
CVE-2020-11308MEDIUM6.8Buffer overflow occurs when trying to convert ASCII string to Unicode string if the actual size is more than required in...
CVE-2020-11305MEDIUM6.8Integer overflow in boot due to improper length check on arguments received in Snapdragon Consumer IOT, Snapdragon Indus...
CVE-2020-11230MEDIUM6.4Potential arbitrary memory corruption when the qseecom driver updates ion physical addresses in the buffer as it exposes...
CVE-2020-11221MEDIUM5.5Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due ...
CVE-2020-11220MEDIUM6.4While processing storage SCM commands there is a time of check or time of use window where a pointer used could be inval...
CVE-2020-11199MEDIUM5.5HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information e...
CVE-2020-11186MEDIUM5.5Modem will enter into busy mode in an infinite loop while parsing histogram dimension due to improper validation of inpu...
CVE-2020-4891MEDIUM5.5IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could...
CVE-2020-4890MEDIUM4.4IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user with a valid role to the RES...
CVE-2020-4851MEDIUM5.5IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which co...
CVE-2020-1926MEDIUM5.9Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing ...
CVE-2020-27290MEDIUM4.3In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilato...
CVE-2020-27282MEDIUM4.3In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in the ventilator allows...
CVE-2020-27278MEDIUM5.2In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, hard-coded credentials in the ventilator allow attackers...
CVE-2020-29556MEDIUM5.5The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files ...
CVE-2020-24982MEDIUM4.3An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick...
CVE-2020-28387MEDIUM5.5A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < ...
CVE-2020-25236MEDIUM5.5A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0...
CVE-2020-14989MEDIUM6.5An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker use...
CVE-2020-14988MEDIUM5.4An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page vi...
CVE-2020-4976MEDIUM4.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us...
CVE-2020-15260MEDIUM6.8PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto...
CVE-2020-35233MEDIUM6.5The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now