2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-9663MEDIUM5.3Adobe Reader Mobile versions 20.0.1 and earlier have a directory traversal vulnerability. Successful exploitation could ...
CVE-2020-15895MEDIUM6.1An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no outp...
CVE-2020-15124MEDIUM6.5In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows for remote attackers to access files on...
CVE-2020-6536MEDIUM4.3Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the use...
CVE-2020-6535MEDIUM6.1Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromis...
CVE-2020-6531MEDIUM4.3Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to l...
CVE-2020-6529MEDIUM4.3Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged networ...
CVE-2020-6528MEDIUM4.3Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the...
CVE-2020-6527MEDIUM4.3Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass conten...
CVE-2020-6526MEDIUM6.5Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypas...
CVE-2020-6521MEDIUM6.5Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain ...
CVE-2020-6519MEDIUM6.5Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy ...
CVE-2020-6516MEDIUM4.3Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a c...
CVE-2020-6514MEDIUM6.5Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged networ...
CVE-2020-6511MEDIUM6.5Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cro...
CVE-2020-6506MEDIUM6.5Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker ...
CVE-2020-8559MEDIUM6.8The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable...
CVE-2020-12774MEDIUM6.7D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary comma...
CVE-2020-15102MEDIUM6.5In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to c...
CVE-2020-14063MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows u...
CVE-2020-15873MEDIUM6.5In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST ...
CVE-2020-12432MEDIUM6.1The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a...
CVE-2020-13932MEDIUM6.1In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or top...
CVE-2020-3442MEDIUM5.7The DuoConnect client enables users to establish SSH connections to hosts protected by a DNG instance. When a user initi...
CVE-2020-1776MEDIUM4.3When an agent user is renamed or set to invalid the session belonging to the user is keept active. The session can not b...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now