2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8154 | HIGH | 7.7 | 1.8% | May 12, 2020 | An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices ... |
| CVE-2020-8153 | HIGH | 8.1 | 1.9% | May 12, 2020 | Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible ... |
| CVE-2020-8151 | HIGH | 7.5 | 2.2% | May 12, 2020 | There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create speci... |
| CVE-2020-11072 | HIGH | 8.6 | 1.0% | May 12, 2020 | In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcom... |
| CVE-2020-11071 | HIGH | 8.6 | 0.9% | May 12, 2020 | SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability where users could experience false-negative validat... |
| CVE-2020-10067 | HIGH | 7.8 | 0.4% | May 11, 2020 | A malicious userspace application can cause a integer overflow and bypass security checks performed by system call handl... |
| CVE-2020-10060 | MEDIUM | 6.5 | 1.6% | May 11, 2020 | In updatehub_probe, right after JSON parsing is complete, objects\[1] is accessed from the output structure in two diffe... |
| CVE-2020-10059 | MEDIUM | 4.8 | 1.2% | May 11, 2020 | The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firm... |
| CVE-2020-10058 | HIGH | 7.8 | 0.4% | May 11, 2020 | Multiple syscalls in the Kscan subsystem perform insufficient argument validation, allowing code executing in userspace ... |
| CVE-2020-10028 | HIGH | 7.8 | 0.4% | May 11, 2020 | Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr ve... |
| CVE-2020-10027 | HIGH | 7.8 | 0.7% | May 11, 2020 | An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. Se... |
| CVE-2020-10026 | — | — | — | May 11, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-10021. Reason: This candidate is a reservation d... |
| CVE-2020-10025 | — | — | — | May 11, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-10067. Reason: This candidate is a reservation d... |
| CVE-2020-10024 | HIGH | 7.8 | 0.7% | May 11, 2020 | The arm platform-specific code uses a signed integer comparison when validating system call numbers. An attacker who has... |
| CVE-2020-10023 | MEDIUM | 6.8 | 0.5% | May 11, 2020 | The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause... |
| CVE-2020-10022 | CRITICAL | 9.8 | 2.3% | May 11, 2020 | A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS. This ... |
| CVE-2020-10021 | HIGH | 7.8 | 0.4% | May 11, 2020 | Out-of-bounds Write in the USB Mass Storage memoryWrite handler with unaligned Sizes See NCC-ZEP-024, NCC-ZEP-025, NCC-Z... |
| CVE-2020-10019 | HIGH | 7.8 | 0.5% | May 11, 2020 | USB DFU has a potential buffer overflow where the requested length (wLength) is not checked against the buffer size. Thi... |
| CVE-2020-1724 | MEDIUM | 4.3 | 0.8% | May 11, 2020 | A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to... |
| CVE-2020-9840 | HIGH | 7.5 | 1.0% | May 11, 2020 | In SwiftNIO Extras before 1.4.1, a logic issue was addressed with improved restrictions. |
| CVE-2020-7647 | MEDIUM | 5.3 | 1.6% | May 11, 2020 | All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby ... |
| CVE-2020-5837 | HIGH | 7.8 | 0.7% | May 11, 2020 | Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replace... |
| CVE-2020-5836 | HIGH | 7.8 | 0.4% | May 11, 2020 | Symantec Endpoint Protection, prior to 14.3, can potentially reset the ACLs on a file as a limited user while Symantec E... |
| CVE-2020-5835 | HIGH | 7 | 0.3% | May 11, 2020 | Symantec Endpoint Protection Manager, prior to 14.3, has a race condition in client remote deployment which may result i... |
| CVE-2020-5834 | MEDIUM | 5.3 | 1.7% | May 11, 2020 | Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now