2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3928CRITICAL9.8GeoVision Door Access Control device family is hardcoded with a root password, which adopting an identical password in a...
CVE-2020-14048HIGH7.5Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the install...
CVE-2020-4045HIGH7.5SSB-DB version 20.0.0 has an information disclosure vulnerability. The get() method is supposed to only decrypt messages...
CVE-2020-13250HIGH7.5HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching f...
CVE-2020-13170HIGH7.5HashiCorp Consul and Consul Enterprise did not appropriately enforce scope for local tokens issued by a primary data cen...
CVE-2020-12797MEDIUM5.3HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to sec...
CVE-2020-12758HIGH7.5HashiCorp Consul and Consul Enterprise could crash when configured with an abnormally-formed service-router entry. Intro...
CVE-2020-12023MEDIUM4.5Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSi...
CVE-2020-13702CRITICAL10The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables atta...
CVE-2020-12725HIGH7.2Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-...
CVE-2020-5411HIGH8.1When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary...
CVE-2020-11614HIGH8.1Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Addition...
CVE-2020-11613HIGH7.8Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions b...
CVE-2020-0233HIGH7.8In main of main.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of...
CVE-2020-0219HIGH7.8In onCreate of SliceDeepLinkSpringBoard.java there is a possible insecure Intent. This could lead to local elevation of ...
CVE-2020-0218HIGH7In loadSoundModel and related functions of SoundTriggerHwService.cpp, there is possible out of bounds write due to a rac...
CVE-2020-0217CRITICAL9.8In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds check. This could l...
CVE-2020-0216HIGH7.8In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow. ...
CVE-2020-0215HIGH7.8In onCreate of ConfirmConnectActivity.java, there is a possible leak of Bluetooth information due to a permissions bypas...
CVE-2020-0214HIGH7.5In ce_t4t_process_select_file_cmd of ce_t4t.cc, there is a possible out of bounds read due to an incorrect bounds check....
CVE-2020-0213MEDIUM6.5In hevcd_fmt_conv_420sp_to_420sp_av8 of ihevcd_fmt_conv_420sp_to_420sp.s, there is a possible out of bounds write due to...
CVE-2020-0212MEDIUM6.5In _onBufferDestroyed of InputBufferManager.cpp, there is a possible out of bounds read due to a use after free. This co...
CVE-2020-0211MEDIUM6.5In SumCompoundHorizontalTaps of convolve_neon.cc, there is a possible out of bounds read due to a missing bounds check. ...
CVE-2020-0210HIGH7.8In removeSharedAccountAsUser of AccountManager.java, there is a possible permissions bypass to a confused deputy. This c...
CVE-2020-0209HIGH7.8In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalatio...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now