2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11524MEDIUM6.6libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.
CVE-2020-11523MEDIUM6.6libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow.
CVE-2020-11522MEDIUM6.5libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read.
CVE-2020-11521MEDIUM6.6libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.
CVE-2020-7809MEDIUM6.1ALSong 3.46 and earlier version contain a Document Object Model (DOM) based cross-site scripting vulnerability caused by...
CVE-2020-9073LOW2.4Huawei P20 smartphones with versions earlier than 10.0.0.156(C00E156R1P4) have an improper authentication vulnerability....
CVE-2020-3810MEDIUM5.5Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service whe...
CVE-2020-1808HIGH7.1Honor 20;HONOR 20 PRO;Honor Magic2;HUAWEI Mate 20 X;HUAWEI P30;HUAWEI P30 Pro;Honor View 20 smartphones with versions ea...
CVE-2020-10744MEDIUM5An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running bec...
CVE-2020-8100HIGH7.5Improper Input Validation vulnerability in the cevakrnl.rv0 module as used in the Bitdefender Engines allows an attacker...
CVE-2020-12882MEDIUM5.4Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a ...
CVE-2020-11931LOW3.3An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to ...
CVE-2020-12440Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-12068MEDIUM6.5An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are...
CVE-2020-12046MEDIUM5.7Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware updat...
CVE-2020-12042MEDIUM6.5Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware ...
CVE-2020-10620CRITICAL9.8Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an at...
CVE-2020-10616HIGH8.8Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC does not specify the path of multiple imported .dll files. Theref...
CVE-2020-10612CRITICAL9.1Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. Ho...
CVE-2020-0221CRITICAL9.8Airbrush FW's scratch memory allocator is susceptible to numeric overflow. When the overflow occurs, the next allocation...
CVE-2020-0220MEDIUM6.7In crus_afe_callback of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. Th...
CVE-2020-0110HIGH7.8In psi_write of psi.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local e...
CVE-2020-0109HIGH7.8In simulatePackageSuspendBroadcast of NotificationManagerService.java, there is a missing permission check. This could l...
CVE-2020-0106MEDIUM5.5In getCellLocation of PhoneInterfaceManager.java, there is a possible permission bypass due to a missing SDK version che...
CVE-2020-0105HIGH7.8In onKeyguardVisibilityChanged of key_store_service.cpp, there is a missing permission check. This could lead to local e...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now