2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-15659HIGH8.8Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of...
CVE-2020-15657HIGH7.8Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker tha...
CVE-2020-15656HIGH8.8JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mit...
CVE-2020-15647HIGH7.4A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, ...
CVE-2020-9528HIGH7.5Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions ...
CVE-2020-9525HIGH8.1CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that...
CVE-2020-8224HIGH7.8A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL confi...
CVE-2020-6145HIGH8.8An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially cr...
CVE-2020-6070HIGH7.8An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A spec...
CVE-2020-13295HIGH8.8For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is sus...
CVE-2020-13293HIGH7.1In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
CVE-2020-12781HIGH8.8Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via mal...
CVE-2020-12780HIGH7.5A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
CVE-2020-12777HIGH7.5A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inje...
CVE-2020-17452HIGH7.2flatCore before 1.5.7 allows upload and execution of a .php file by an admin.
CVE-2020-15827HIGH7.5In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe...
CVE-2020-15825HIGH8.8In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.
CVE-2020-15824HIGH8.8In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there ...
CVE-2020-15823HIGH7.5JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
CVE-2020-15817HIGH8.8In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.
CVE-2020-15063HIGH8.8DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to bypass auth...
CVE-2020-15062HIGH8.8DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate pri...
CVE-2020-15059HIGH8.8Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass auth...
CVE-2020-15058HIGH8.8Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate pri...
CVE-2020-15055HIGH8.8TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to bypass auth...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now