2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-26958MEDIUM6.1Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached throug...
CVE-2020-26957MEDIUM6.5OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a...
CVE-2020-26956MEDIUM6.1In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to X...
CVE-2020-26955MEDIUM6.5When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent...
CVE-2020-26954MEDIUM4.3When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file ...
CVE-2020-26953MEDIUM4.3It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possibl...
CVE-2020-26951MEDIUM6.1A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitizati...
CVE-2020-25627MEDIUM6.1The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3....
CVE-2020-10146MEDIUM5.4The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter tha...
CVE-2020-26234MEDIUM4.8Opencast before versions 8.9 and 7.9 disables HTTPS hostname verification of its HTTP client used for a large portion of...
CVE-2020-27896MEDIUM5.5A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1. A remote atta...
CVE-2020-27821MEDIUM6A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue cou...
CVE-2020-27756MEDIUM5.5In ParseMetaGeometry() of MagickCore/geometry.c, image height and width calculations can lead to divide-by-zero conditio...
CVE-2020-27753MEDIUM5.5There are several memory leaks in the MIFF coder in /coders/miff.c due to improper image depth values, which can be trig...
CVE-2020-27750MEDIUM5.5A flaw was found in ImageMagick in MagickCore/colorspace-private.h and MagickCore/quantum.h. An attacker who submits a c...
CVE-2020-26256MEDIUM6.5Fast-csv is an npm package for parsing and formatting CSVs or any other delimited value file in node. In fast-cvs before...
CVE-2020-25676MEDIUM5.5In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and InterpolatePixelInfo()...
CVE-2020-25674MEDIUM5.5WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an ou...
CVE-2020-27950MEDIUM5.5A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch...
CVE-2020-27929MEDIUM5.5A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. T...
CVE-2020-27925MEDIUM5.5An issue existed in the handling of incoming calls. The issue was addressed with additional state checks. This issue is ...
CVE-2020-27902MEDIUM4.6An authentication issue was addressed with improved state management. This issue is fixed in iOS 14.2 and iPadOS 14.2. A...
CVE-2020-27900MEDIUM5.5An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fix...
CVE-2020-27898MEDIUM5.5A denial of service issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1. An at...
CVE-2020-25667MEDIUM5.5TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for `"dc:for...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now