2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13839CRITICAL9.8An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can...
CVE-2020-13849HIGH7.5The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client...
CVE-2020-13768CRITICAL9.8In MiniShare before 1.4.2, there is a stack-based buffer overflow via an HTTP PUT request, which allows an attacker to a...
CVE-2020-13848HIGH7.5Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a cr...
CVE-2020-12853MEDIUM6.1Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially maliciou...
CVE-2020-12852MEDIUM6.8The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key ...
CVE-2020-12851HIGH8.1Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells...
CVE-2020-12847HIGH7.2Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with...
CVE-2020-11682MEDIUM6.5Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by th...
CVE-2020-11681HIGH8.1Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged us...
CVE-2020-11680MEDIUM6.5Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fail...
CVE-2020-11679HIGH8.8Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionalit...
CVE-2020-7661HIGH7.5all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long stri...
CVE-2020-13838LOW3.5An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The DeX Lockscreen feature does not ...
CVE-2020-13837LOW3.5An issue was discovered on Samsung mobile devices with Q(10.0) software. The Lockscreen feature does not block Quick Pan...
CVE-2020-13836HIGH7.5An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path ...
CVE-2020-13835CRITICAL9.8An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a ...
CVE-2020-13834HIGH7.5An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folde...
CVE-2020-13833CRITICAL9.1An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbi...
CVE-2020-13832CRITICAL9.8An issue was discovered on Samsung mobile devices with Q(10.0) (with TEEGRIS on Exynos chipsets) software. The Widevine ...
CVE-2020-13831CRITICAL9.8An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 7570 chipsets) software. The Trustonic ...
CVE-2020-13830HIGH7.5An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Sa...
CVE-2020-13829HIGH7.5An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can disable the SEAndroid ...
CVE-2020-10702MEDIUM5.5A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in versi...
CVE-2020-9462MEDIUM4.3An issue was discovered in all Athom Homey and Homey Pro devices up to the current version 4.2.0. An attacker within RF ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now