2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11798 | MEDIUM | 5.3 | 45.2% | Jun 10, 2020 | A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before ... |
| CVE-2020-0121 | MEDIUM | 5.5 | 0.3% | Jun 10, 2020 | In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead... |
| CVE-2020-0119 | MEDIUM | 5.3 | 0.7% | Jun 10, 2020 | In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle att... |
| CVE-2020-0118 | HIGH | 7.8 | 0.2% | Jun 10, 2020 | In addListener of RegionSamplingThread.cpp, there is a possible out of bounds write due to improper input validation. Th... |
| CVE-2020-0117 | CRITICAL | 9.8 | 1.6% | Jun 10, 2020 | In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remot... |
| CVE-2020-0116 | MEDIUM | 5.5 | 0.2% | Jun 10, 2020 | In checkSystemLocationAccess of LocationAccessPolicy.java, there is a possible bypass of user profile isolation due to a... |
| CVE-2020-0115 | HIGH | 7.8 | 0.2% | Jun 10, 2020 | In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to bec... |
| CVE-2020-0114 | HIGH | 7.8 | 0.3% | Jun 10, 2020 | In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error... |
| CVE-2020-0113 | MEDIUM | 5.5 | 0.4% | Jun 10, 2020 | In sendCaptureResult of Camera3OutputUtils.cpp, there is a possible out of bounds read due to a use after free. This cou... |
| CVE-2020-7589 | CRITICAL | 9.1 | 2.0% | Jun 10, 2020 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead t... |
| CVE-2020-7586 | HIGH | 7.8 | 0.4% | Jun 10, 2020 | A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions <... |
| CVE-2020-7585 | HIGH | 7.8 | 0.4% | Jun 10, 2020 | A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions <... |
| CVE-2020-7580 | MEDIUM | 6.7 | 0.4% | Jun 10, 2020 | A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All... |
| CVE-2020-10755 | MEDIUM | 6.5 | 1.2% | Jun 10, 2020 | An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-ci... |
| CVE-2020-7675 | CRITICAL | 9.8 | 2.5% | Jun 10, 2020 | cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument execu... |
| CVE-2020-7674 | CRITICAL | 9.8 | 2.5% | Jun 10, 2020 | access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is... |
| CVE-2020-7673 | CRITICAL | 9.8 | 2.5% | Jun 10, 2020 | node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend`... |
| CVE-2020-7672 | HIGH | 8.6 | 1.9% | Jun 10, 2020 | mosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to `properties` argument is executed b... |
| CVE-2020-7671 | HIGH | 7.5 | 1.2% | Jun 10, 2020 | goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also bein... |
| CVE-2020-7670 | HIGH | 7.5 | 1.2% | Jun 10, 2020 | agoo prior to 2.14.0 allows request smuggling attacks where agoo is used as a backend and a frontend proxy also being vu... |
| CVE-2020-13271 | MEDIUM | 6.1 | 1.5% | Jun 10, 2020 | A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all p... |
| CVE-2020-13270 | HIGH | 8.8 | 1.4% | Jun 10, 2020 | Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to c... |
| CVE-2020-13269 | MEDIUM | 6.1 | 1.8% | Jun 10, 2020 | A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Edi... |
| CVE-2020-13268 | MEDIUM | 5.3 | 1.1% | Jun 10, 2020 | A specially crafted request could be used to confirm the existence of files hosted on object storage services, without d... |
| CVE-2020-13267 | MEDIUM | 6.1 | 1.8% | Jun 10, 2020 | A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in Git... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now