2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9663 | MEDIUM | 5.3 | 3.2% | Jul 22, 2020 | Adobe Reader Mobile versions 20.0.1 and earlier have a directory traversal vulnerability. Successful exploitation could ... |
| CVE-2020-15895 | MEDIUM | 6.1 | 2.8% | Jul 22, 2020 | An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no outp... |
| CVE-2020-15124 | MEDIUM | 6.5 | 1.5% | Jul 22, 2020 | In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows for remote attackers to access files on... |
| CVE-2020-6536 | MEDIUM | 4.3 | 1.4% | Jul 22, 2020 | Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the use... |
| CVE-2020-6535 | MEDIUM | 6.1 | 1.4% | Jul 22, 2020 | Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromis... |
| CVE-2020-6531 | MEDIUM | 4.3 | 1.6% | Jul 22, 2020 | Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to l... |
| CVE-2020-6529 | MEDIUM | 4.3 | 1.3% | Jul 22, 2020 | Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged networ... |
| CVE-2020-6528 | MEDIUM | 4.3 | 1.5% | Jul 22, 2020 | Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the... |
| CVE-2020-6527 | MEDIUM | 4.3 | 1.5% | Jul 22, 2020 | Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass conten... |
| CVE-2020-6526 | MEDIUM | 6.5 | 1.7% | Jul 22, 2020 | Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypas... |
| CVE-2020-6521 | MEDIUM | 6.5 | 1.7% | Jul 22, 2020 | Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain ... |
| CVE-2020-6519 | MEDIUM | 6.5 | 11.3% | Jul 22, 2020 | Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy ... |
| CVE-2020-6516 | MEDIUM | 4.3 | 4.8% | Jul 22, 2020 | Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a c... |
| CVE-2020-6514 | MEDIUM | 6.5 | 7.8% | Jul 22, 2020 | Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged networ... |
| CVE-2020-6511 | MEDIUM | 6.5 | 1.7% | Jul 22, 2020 | Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cro... |
| CVE-2020-6506 | MEDIUM | 6.5 | 3.8% | Jul 22, 2020 | Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker ... |
| CVE-2020-8559 | MEDIUM | 6.8 | 6.1% | Jul 22, 2020 | The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable... |
| CVE-2020-12774 | MEDIUM | 6.7 | 0.4% | Jul 22, 2020 | D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary comma... |
| CVE-2020-15102 | MEDIUM | 6.5 | 0.7% | Jul 21, 2020 | In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to c... |
| CVE-2020-14063 | MEDIUM | 6.1 | 1.4% | Jul 21, 2020 | A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows u... |
| CVE-2020-15873 | MEDIUM | 6.5 | 2.2% | Jul 21, 2020 | In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST ... |
| CVE-2020-12432 | MEDIUM | 6.1 | 0.9% | Jul 21, 2020 | The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a... |
| CVE-2020-13932 | MEDIUM | 6.1 | 4.3% | Jul 20, 2020 | In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or top... |
| CVE-2020-3442 | MEDIUM | 5.7 | 0.2% | Jul 20, 2020 | The DuoConnect client enables users to establish SSH connections to hosts protected by a DNG instance. When a user initi... |
| CVE-2020-1776 | MEDIUM | 4.3 | 0.9% | Jul 20, 2020 | When an agent user is renamed or set to invalid the session belonging to the user is keept active. The session can not b... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now