2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8154HIGH7.7An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices ...
CVE-2020-8153HIGH8.1Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible ...
CVE-2020-8151HIGH7.5There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create speci...
CVE-2020-11072HIGH8.6In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcom...
CVE-2020-11071HIGH8.6SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability where users could experience false-negative validat...
CVE-2020-10067HIGH7.8A malicious userspace application can cause a integer overflow and bypass security checks performed by system call handl...
CVE-2020-10060MEDIUM6.5In updatehub_probe, right after JSON parsing is complete, objects\[1] is accessed from the output structure in two diffe...
CVE-2020-10059MEDIUM4.8The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firm...
CVE-2020-10058HIGH7.8Multiple syscalls in the Kscan subsystem perform insufficient argument validation, allowing code executing in userspace ...
CVE-2020-10028HIGH7.8Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr ve...
CVE-2020-10027HIGH7.8An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. Se...
CVE-2020-10026Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-10021. Reason: This candidate is a reservation d...
CVE-2020-10025Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-10067. Reason: This candidate is a reservation d...
CVE-2020-10024HIGH7.8The arm platform-specific code uses a signed integer comparison when validating system call numbers. An attacker who has...
CVE-2020-10023MEDIUM6.8The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause...
CVE-2020-10022CRITICAL9.8A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS. This ...
CVE-2020-10021HIGH7.8Out-of-bounds Write in the USB Mass Storage memoryWrite handler with unaligned Sizes See NCC-ZEP-024, NCC-ZEP-025, NCC-Z...
CVE-2020-10019HIGH7.8USB DFU has a potential buffer overflow where the requested length (wLength) is not checked against the buffer size. Thi...
CVE-2020-1724MEDIUM4.3A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to...
CVE-2020-9840HIGH7.5In SwiftNIO Extras before 1.4.1, a logic issue was addressed with improved restrictions.
CVE-2020-7647MEDIUM5.3All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby ...
CVE-2020-5837HIGH7.8Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replace...
CVE-2020-5836HIGH7.8Symantec Endpoint Protection, prior to 14.3, can potentially reset the ACLs on a file as a limited user while Symantec E...
CVE-2020-5835HIGH7Symantec Endpoint Protection Manager, prior to 14.3, has a race condition in client remote deployment which may result i...
CVE-2020-5834MEDIUM5.3Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now