2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-0133HIGH7.3In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions ...
CVE-2020-0132MEDIUM5.5In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserializati...
CVE-2020-0131HIGH8.8In parseChunk of MPEG4Extractor.cpp, there is a possible out of bounds write due to incompletely initialized data. This ...
CVE-2020-0129HIGH7.8In SetData of btm_ble_multi_adv.cc, there is a possible out-of-bound write due to an incorrect bounds check. This could ...
CVE-2020-0128HIGH7.5In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow. This could lead to...
CVE-2020-0127MEDIUM6.5In AudioStream::decode of AudioGroup.cpp, there is a possible out of bounds read due to a missing bounds check. This cou...
CVE-2020-0126MEDIUM6.4In multiple functions in DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to l...
CVE-2020-0124MEDIUM6.7In markBootComplete of InstalldNativeService.cpp, there is a possible out of bounds write due to a missing bounds check....
CVE-2020-6090HIGH7.2An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03...
CVE-2020-4101CRITICAL9.8"HCL Digital Experience is susceptible to Server Side Request Forgery."
CVE-2020-12712HIGH7.5A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an...
CVE-2020-4380MEDIUM5.4IBM Workload Scheduler 9.3.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary...
CVE-2020-5593HIGH8.8Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a ...
CVE-2020-5592MEDIUM6.1Cross-site scripting vulnerability in Zenphoto versions prior to 1.5.7 allows remote attackers to inject an arbitrary Ja...
CVE-2020-13855HIGH7.2Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manag...
CVE-2020-13854CRITICAL9.8Artica Pandora FMS 7.44 allows privilege escalation.
CVE-2020-13853MEDIUM5.4Artica Pandora FMS 7.44 has persistent XSS in the Messages feature.
CVE-2020-13852HIGH7.2Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.
CVE-2020-13851HIGH8.8Artica Pandora FMS 7.44 allows remote command execution via the events feature.
CVE-2020-13850HIGH7.5Artica Pandora FMS 7.44 has inadequate access controls on a web folder.
CVE-2020-13998MEDIUM5.3Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on t...
CVE-2020-12850HIGH7The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Ce...
CVE-2020-12714MEDIUM5.9An issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual A...
CVE-2020-12713HIGH7.2An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and Ci...
CVE-2020-11090HIGH7.5In Indy Node 1.12.2, there is an Uncontrolled Resource Consumption vulnerability. Indy Node has a bug in TAA handling co...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now