2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-23160HIGH8.8Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to...
CVE-2020-22643HIGH7.2Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. A...
CVE-2020-16236HIGH7.8FPWIN Pro is vulnerable to an out-of-bounds read vulnerability when a user opens a maliciously crafted project file, whi...
CVE-2020-0236HIGH7.5In A2DP_GetCodecType of a2dp_codec_config, there is a possible out-of-bounds read due to improper input validation. This...
CVE-2020-4949HIGH8.2IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack w...
CVE-2020-17532HIGH8.8When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause ...
CVE-2020-12525HIGH7.8M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deser...
CVE-2020-12513HIGH8.8Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection...
CVE-2020-12511HIGH8.8Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the ...
CVE-2020-4766HIGH7.5IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ dat...
CVE-2020-26295HIGH7.2OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrat...
CVE-2020-26285HIGH7.2OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vul...
CVE-2020-3685HIGH7.5Pointer variable which is freed is not cleared can result in memory corruption and leads to denial of service in Snapdra...
CVE-2020-11217HIGH7.8A possible double free or invalid memory access in audio driver while reading Speaker Protection parameters in Snapdrago...
CVE-2020-11214HIGH7.5Buffer over-read while processing NDL attribute if attribute length is larger than expected and then FW is treating it a...
CVE-2020-11200HIGH7.5Buffer over-read while parsing RPS due to lack of check of input validation on values received from user side. in Snapdr...
CVE-2020-11185HIGH7.8Out of bound issue in WLAN driver while processing vdev responses from firmware due to lack of validation of data receiv...
CVE-2020-11181HIGH7.8Out of bound access issue while handling cvp process control command due to improper validation of buffer pointer receiv...
CVE-2020-11180HIGH7.8Out of bound access in computer vision control due to improper validation of command length before processing it in Snap...
CVE-2020-11179HIGH7Arbitrary read and write to kernel addresses by temporarily overwriting ring buffer pointer and creating a race conditio...
CVE-2020-11146HIGH7.8Out of bound write while copying data using IOCTL due to lack of check of array index received from user in Snapdragon A...
CVE-2020-11145HIGH7.5Divide by zero issue can happen while updating delta extension header due to improper validation of master SN and extens...
CVE-2020-11139HIGH7.5Out of bound memory access while processing frames due to lack of check of invalid frames received in Snapdragon Auto, S...
CVE-2020-11119HIGH7.5Buffer over-read can happen when the buffer length received from response handlers is more than the size of the payload ...
CVE-2020-26278HIGH8Weave Net is open source software which creates a virtual network that connects Docker containers across multiple hosts ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now