2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-23160 | HIGH | 8.8 | 6.9% | Jan 26, 2021 | Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to... |
| CVE-2020-22643 | HIGH | 7.2 | 1.9% | Jan 26, 2021 | Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. A... |
| CVE-2020-16236 | HIGH | 7.8 | 1.2% | Jan 26, 2021 | FPWIN Pro is vulnerable to an out-of-bounds read vulnerability when a user opens a maliciously crafted project file, whi... |
| CVE-2020-0236 | HIGH | 7.5 | 0.8% | Jan 26, 2021 | In A2DP_GetCodecType of a2dp_codec_config, there is a possible out-of-bounds read due to improper input validation. This... |
| CVE-2020-4949 | HIGH | 8.2 | 4.8% | Jan 26, 2021 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack w... |
| CVE-2020-17532 | HIGH | 8.8 | 3.2% | Jan 25, 2021 | When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause ... |
| CVE-2020-12525 | HIGH | 7.8 | 1.3% | Jan 22, 2021 | M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deser... |
| CVE-2020-12513 | HIGH | 8.8 | 31.1% | Jan 22, 2021 | Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection... |
| CVE-2020-12511 | HIGH | 8.8 | 0.6% | Jan 22, 2021 | Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the ... |
| CVE-2020-4766 | HIGH | 7.5 | 1.5% | Jan 22, 2021 | IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ dat... |
| CVE-2020-26295 | HIGH | 7.2 | 1.8% | Jan 21, 2021 | OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrat... |
| CVE-2020-26285 | HIGH | 7.2 | 2.9% | Jan 21, 2021 | OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vul... |
| CVE-2020-3685 | HIGH | 7.5 | 0.9% | Jan 21, 2021 | Pointer variable which is freed is not cleared can result in memory corruption and leads to denial of service in Snapdra... |
| CVE-2020-11217 | HIGH | 7.8 | 0.2% | Jan 21, 2021 | A possible double free or invalid memory access in audio driver while reading Speaker Protection parameters in Snapdrago... |
| CVE-2020-11214 | HIGH | 7.5 | 0.8% | Jan 21, 2021 | Buffer over-read while processing NDL attribute if attribute length is larger than expected and then FW is treating it a... |
| CVE-2020-11200 | HIGH | 7.5 | 0.8% | Jan 21, 2021 | Buffer over-read while parsing RPS due to lack of check of input validation on values received from user side. in Snapdr... |
| CVE-2020-11185 | HIGH | 7.8 | 0.2% | Jan 21, 2021 | Out of bound issue in WLAN driver while processing vdev responses from firmware due to lack of validation of data receiv... |
| CVE-2020-11181 | HIGH | 7.8 | 0.2% | Jan 21, 2021 | Out of bound access issue while handling cvp process control command due to improper validation of buffer pointer receiv... |
| CVE-2020-11180 | HIGH | 7.8 | 0.2% | Jan 21, 2021 | Out of bound access in computer vision control due to improper validation of command length before processing it in Snap... |
| CVE-2020-11179 | HIGH | 7 | 0.3% | Jan 21, 2021 | Arbitrary read and write to kernel addresses by temporarily overwriting ring buffer pointer and creating a race conditio... |
| CVE-2020-11146 | HIGH | 7.8 | 0.2% | Jan 21, 2021 | Out of bound write while copying data using IOCTL due to lack of check of array index received from user in Snapdragon A... |
| CVE-2020-11145 | HIGH | 7.5 | 0.8% | Jan 21, 2021 | Divide by zero issue can happen while updating delta extension header due to improper validation of master SN and extens... |
| CVE-2020-11139 | HIGH | 7.5 | 0.8% | Jan 21, 2021 | Out of bound memory access while processing frames due to lack of check of invalid frames received in Snapdragon Auto, S... |
| CVE-2020-11119 | HIGH | 7.5 | 0.8% | Jan 21, 2021 | Buffer over-read can happen when the buffer length received from response handlers is more than the size of the payload ... |
| CVE-2020-26278 | HIGH | 8 | 0.7% | Jan 20, 2021 | Weave Net is open source software which creates a virtual network that connects Docker containers across multiple hosts ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now