2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26958 | MEDIUM | 6.1 | 1.3% | Dec 9, 2020 | Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached throug... |
| CVE-2020-26957 | MEDIUM | 6.5 | 0.5% | Dec 9, 2020 | OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a... |
| CVE-2020-26956 | MEDIUM | 6.1 | 1.2% | Dec 9, 2020 | In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to X... |
| CVE-2020-26955 | MEDIUM | 6.5 | 0.8% | Dec 9, 2020 | When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent... |
| CVE-2020-26954 | MEDIUM | 4.3 | 0.6% | Dec 9, 2020 | When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file ... |
| CVE-2020-26953 | MEDIUM | 4.3 | 1.3% | Dec 9, 2020 | It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possibl... |
| CVE-2020-26951 | MEDIUM | 6.1 | 1.0% | Dec 9, 2020 | A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitizati... |
| CVE-2020-25627 | MEDIUM | 6.1 | 3.7% | Dec 9, 2020 | The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.... |
| CVE-2020-10146 | MEDIUM | 5.4 | 1.9% | Dec 9, 2020 | The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter tha... |
| CVE-2020-26234 | MEDIUM | 4.8 | 0.3% | Dec 8, 2020 | Opencast before versions 8.9 and 7.9 disables HTTPS hostname verification of its HTTP client used for a large portion of... |
| CVE-2020-27896 | MEDIUM | 5.5 | 1.4% | Dec 8, 2020 | A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1. A remote atta... |
| CVE-2020-27821 | MEDIUM | 6 | 0.4% | Dec 8, 2020 | A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue cou... |
| CVE-2020-27756 | MEDIUM | 5.5 | 0.8% | Dec 8, 2020 | In ParseMetaGeometry() of MagickCore/geometry.c, image height and width calculations can lead to divide-by-zero conditio... |
| CVE-2020-27753 | MEDIUM | 5.5 | 0.9% | Dec 8, 2020 | There are several memory leaks in the MIFF coder in /coders/miff.c due to improper image depth values, which can be trig... |
| CVE-2020-27750 | MEDIUM | 5.5 | 1.0% | Dec 8, 2020 | A flaw was found in ImageMagick in MagickCore/colorspace-private.h and MagickCore/quantum.h. An attacker who submits a c... |
| CVE-2020-26256 | MEDIUM | 6.5 | 1.5% | Dec 8, 2020 | Fast-csv is an npm package for parsing and formatting CSVs or any other delimited value file in node. In fast-cvs before... |
| CVE-2020-25676 | MEDIUM | 5.5 | 1.2% | Dec 8, 2020 | In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and InterpolatePixelInfo()... |
| CVE-2020-25674 | MEDIUM | 5.5 | 1.0% | Dec 8, 2020 | WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an ou... |
| CVE-2020-27950 | MEDIUM | 5.5 | 16.5% | Dec 8, 2020 | A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch... |
| CVE-2020-27929 | MEDIUM | 5.5 | 0.6% | Dec 8, 2020 | A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. T... |
| CVE-2020-27925 | MEDIUM | 5.5 | 0.3% | Dec 8, 2020 | An issue existed in the handling of incoming calls. The issue was addressed with additional state checks. This issue is ... |
| CVE-2020-27902 | MEDIUM | 4.6 | 0.3% | Dec 8, 2020 | An authentication issue was addressed with improved state management. This issue is fixed in iOS 14.2 and iPadOS 14.2. A... |
| CVE-2020-27900 | MEDIUM | 5.5 | 0.9% | Dec 8, 2020 | An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fix... |
| CVE-2020-27898 | MEDIUM | 5.5 | 1.0% | Dec 8, 2020 | A denial of service issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1. An at... |
| CVE-2020-25667 | MEDIUM | 5.5 | 1.2% | Dec 8, 2020 | TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for `"dc:for... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now