2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11798MEDIUM5.3A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before ...
CVE-2020-0121MEDIUM5.5In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead...
CVE-2020-0119MEDIUM5.3In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle att...
CVE-2020-0118HIGH7.8In addListener of RegionSamplingThread.cpp, there is a possible out of bounds write due to improper input validation. Th...
CVE-2020-0117CRITICAL9.8In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remot...
CVE-2020-0116MEDIUM5.5In checkSystemLocationAccess of LocationAccessPolicy.java, there is a possible bypass of user profile isolation due to a...
CVE-2020-0115HIGH7.8In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to bec...
CVE-2020-0114HIGH7.8In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error...
CVE-2020-0113MEDIUM5.5In sendCaptureResult of Camera3OutputUtils.cpp, there is a possible out of bounds read due to a use after free. This cou...
CVE-2020-7589CRITICAL9.1A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead t...
CVE-2020-7586HIGH7.8A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions <...
CVE-2020-7585HIGH7.8A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions <...
CVE-2020-7580MEDIUM6.7A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All...
CVE-2020-10755MEDIUM6.5An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-ci...
CVE-2020-7675CRITICAL9.8cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument execu...
CVE-2020-7674CRITICAL9.8access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is...
CVE-2020-7673CRITICAL9.8node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend`...
CVE-2020-7672HIGH8.6mosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to `properties` argument is executed b...
CVE-2020-7671HIGH7.5goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also bein...
CVE-2020-7670HIGH7.5agoo prior to 2.14.0 allows request smuggling attacks where agoo is used as a backend and a frontend proxy also being vu...
CVE-2020-13271MEDIUM6.1A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all p...
CVE-2020-13270HIGH8.8Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to c...
CVE-2020-13269MEDIUM6.1A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Edi...
CVE-2020-13268MEDIUM5.3A specially crafted request could be used to confirm the existence of files hosted on object storage services, without d...
CVE-2020-13267MEDIUM6.1A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in Git...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now