2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27692 | HIGH | 8.8 | 0.5% | Nov 4, 2020 | The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within ... |
| CVE-2020-7129 | HIGH | 7.2 | 2.6% | Nov 4, 2020 | A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3... |
| CVE-2020-8037 | HIGH | 7.5 | 3.1% | Nov 4, 2020 | The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. |
| CVE-2020-8036 | HIGH | 7.5 | 1.4% | Nov 4, 2020 | The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way. |
| CVE-2020-22278 | HIGH | 8.8 | 1.5% | Nov 4, 2020 | phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file i... |
| CVE-2020-22277 | HIGH | 8 | 1.8% | Nov 4, 2020 | Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile. |
| CVE-2020-22275 | HIGH | 8.8 | 2.1% | Nov 4, 2020 | Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV comma... |
| CVE-2020-26211 | HIGH | 8.7 | 1.1% | Nov 3, 2020 | In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use ... |
| CVE-2020-26210 | HIGH | 8.7 | 1.2% | Nov 3, 2020 | In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execut... |
| CVE-2020-16009 | HIGH | 8.8 | 48.6% | Nov 3, 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially expl... |
| CVE-2020-16008 | HIGH | 8.8 | 1.1% | Nov 3, 2020 | Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit... |
| CVE-2020-16007 | HIGH | 7.8 | 0.3% | Nov 3, 2020 | Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentiall... |
| CVE-2020-16006 | HIGH | 8.8 | 1.7% | Nov 3, 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially expl... |
| CVE-2020-16005 | HIGH | 8.8 | 1.7% | Nov 3, 2020 | Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentiall... |
| CVE-2020-16004 | HIGH | 8.8 | 1.5% | Nov 3, 2020 | Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploi... |
| CVE-2020-16003 | HIGH | 8.8 | 1.5% | Nov 3, 2020 | Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap... |
| CVE-2020-16002 | HIGH | 8.8 | 1.6% | Nov 3, 2020 | Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap c... |
| CVE-2020-16001 | HIGH | 8.8 | 1.6% | Nov 3, 2020 | Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap co... |
| CVE-2020-16000 | HIGH | 8.8 | 1.6% | Nov 3, 2020 | Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially e... |
| CVE-2020-15998 | HIGH | 8.8 | 0.7% | Nov 3, 2020 | Use after free in USB in Google Chrome prior to 86.0.4240.99 allowed a remote attacker who had compromised the renderer ... |
| CVE-2020-15997 | HIGH | 8.8 | 0.9% | Nov 3, 2020 | Use after free in Mojo in Google Chrome prior to 86.0.4240.99 allowed a remote attacker who had compromised the renderer... |
| CVE-2020-15996 | HIGH | 8.8 | 0.8% | Nov 3, 2020 | Use after free in passwords in Google Chrome prior to 86.0.4240.99 allowed a remote attacker who had compromised the ren... |
| CVE-2020-15995 | HIGH | 8.8 | 1.3% | Nov 3, 2020 | Out of bounds write in V8 in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap c... |
| CVE-2020-15994 | HIGH | 8.8 | 13.1% | Nov 3, 2020 | Use after free in V8 in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corrup... |
| CVE-2020-15992 | HIGH | 8.8 | 1.4% | Nov 3, 2020 | Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had c... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now