2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15659 | HIGH | 8.8 | 2.4% | Aug 10, 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of... |
| CVE-2020-15657 | HIGH | 7.8 | 0.4% | Aug 10, 2020 | Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker tha... |
| CVE-2020-15656 | HIGH | 8.8 | 1.5% | Aug 10, 2020 | JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mit... |
| CVE-2020-15647 | HIGH | 7.4 | 1.1% | Aug 10, 2020 | A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, ... |
| CVE-2020-9528 | HIGH | 7.5 | 0.8% | Aug 10, 2020 | Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions ... |
| CVE-2020-9525 | HIGH | 8.1 | 1.6% | Aug 10, 2020 | CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that... |
| CVE-2020-8224 | HIGH | 7.8 | 0.7% | Aug 10, 2020 | A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL confi... |
| CVE-2020-6145 | HIGH | 8.8 | 1.8% | Aug 10, 2020 | An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially cr... |
| CVE-2020-6070 | HIGH | 7.8 | 1.7% | Aug 10, 2020 | An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A spec... |
| CVE-2020-13295 | HIGH | 8.8 | 1.2% | Aug 10, 2020 | For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is sus... |
| CVE-2020-13293 | HIGH | 7.1 | 1.0% | Aug 10, 2020 | In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash. |
| CVE-2020-12781 | HIGH | 8.8 | 0.5% | Aug 10, 2020 | Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via mal... |
| CVE-2020-12780 | HIGH | 7.5 | 1.2% | Aug 10, 2020 | A security misconfiguration exists in Combodo iTop, which can expose sensitive information. |
| CVE-2020-12777 | HIGH | 7.5 | 1.3% | Aug 10, 2020 | A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inje... |
| CVE-2020-17452 | HIGH | 7.2 | 2.4% | Aug 9, 2020 | flatCore before 1.5.7 allows upload and execution of a .php file by an admin. |
| CVE-2020-15827 | HIGH | 7.5 | 0.7% | Aug 8, 2020 | In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe... |
| CVE-2020-15825 | HIGH | 8.8 | 1.1% | Aug 8, 2020 | In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges. |
| CVE-2020-15824 | HIGH | 8.8 | 1.8% | Aug 8, 2020 | In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there ... |
| CVE-2020-15823 | HIGH | 7.5 | 2.0% | Aug 8, 2020 | JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component. |
| CVE-2020-15817 | HIGH | 8.8 | 2.0% | Aug 8, 2020 | In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues. |
| CVE-2020-15063 | HIGH | 8.8 | 0.9% | Aug 7, 2020 | DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to bypass auth... |
| CVE-2020-15062 | HIGH | 8.8 | 0.3% | Aug 7, 2020 | DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate pri... |
| CVE-2020-15059 | HIGH | 8.8 | 0.9% | Aug 7, 2020 | Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass auth... |
| CVE-2020-15058 | HIGH | 8.8 | 0.3% | Aug 7, 2020 | Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate pri... |
| CVE-2020-15055 | HIGH | 8.8 | 0.9% | Aug 7, 2020 | TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to bypass auth... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now