2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6541 | HIGH | 8.8 | 22.9% | Sep 21, 2020 | Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap c... |
| CVE-2020-6540 | HIGH | 8.8 | 1.5% | Sep 21, 2020 | Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap co... |
| CVE-2020-6539 | HIGH | 8.8 | 1.0% | Sep 21, 2020 | Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2020-6537 | HIGH | 8.8 | 1.6% | Sep 21, 2020 | Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside ... |
| CVE-2020-6532 | HIGH | 8.8 | 1.3% | Sep 21, 2020 | Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2020-15965 | HIGH | 8.8 | 3.4% | Sep 21, 2020 | Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bou... |
| CVE-2020-15964 | HIGH | 8.8 | 2.9% | Sep 21, 2020 | Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially e... |
| CVE-2020-15962 | HIGH | 8.8 | 1.9% | Sep 21, 2020 | Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentiall... |
| CVE-2020-15960 | HIGH | 8.8 | 1.9% | Sep 21, 2020 | Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform... |
| CVE-2020-4643 | HIGH | 7.5 | 2.8% | Sep 21, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack w... |
| CVE-2020-4581 | HIGH | 7.5 | 1.6% | Sep 21, 2020 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sendi... |
| CVE-2020-4580 | HIGH | 7.5 | 1.6% | Sep 21, 2020 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sendi... |
| CVE-2020-4579 | HIGH | 7.5 | 2.2% | Sep 21, 2020 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sendi... |
| CVE-2020-25796 | HIGH | 7.5 | 1.6% | Sep 19, 2020 | An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the InlineArray implementation, an unaligne... |
| CVE-2020-25795 | HIGH | 7.5 | 1.7% | Sep 19, 2020 | An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, insert_from can h... |
| CVE-2020-25794 | HIGH | 7.5 | 1.7% | Sep 19, 2020 | An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, clone can have a ... |
| CVE-2020-25793 | HIGH | 7.5 | 1.6% | Sep 19, 2020 | An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is... |
| CVE-2020-25792 | HIGH | 7.5 | 2.8% | Sep 19, 2020 | An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is... |
| CVE-2020-25791 | HIGH | 7.5 | 1.7% | Sep 19, 2020 | An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is... |
| CVE-2020-25790 | HIGH | 7.2 | 15.6% | Sep 19, 2020 | Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi... |
| CVE-2020-25788 | HIGH | 8.1 | 1.2% | Sep 19, 2020 | An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mish... |
| CVE-2020-8253 | HIGH | 7.5 | 1.7% | Sep 18, 2020 | Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix Xe... |
| CVE-2020-8252 | HIGH | 7.8 | 0.7% | Sep 18, 2020 | The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined th... |
| CVE-2020-8251 | HIGH | 7.5 | 8.8% | Sep 18, 2020 | Node.js < 14.11.0 is vulnerable to HTTP denial of service (DoS) attacks based on delayed requests submission which can m... |
| CVE-2020-8247 | HIGH | 8.8 | 1.4% | Sep 18, 2020 | Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix AD... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now