2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-6510HIGH7.8Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially...
CVE-2020-6507HIGH8.8Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap ...
CVE-2020-15890HIGH7.5LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
CVE-2020-15888HIGH8.8Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffe...
CVE-2020-15724HIGH7.8In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a loca...
CVE-2020-15723HIGH7.8In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome...
CVE-2020-15722HIGH7.8In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privileg...
CVE-2020-15879HIGH7.5Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe,...
CVE-2020-15877HIGH8.8An issue was discovered in LibreNMS before 1.65.1. It has insufficient access control for normal users because of "'guar...
CVE-2020-12499HIGH7.3In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on imp...
CVE-2020-4125HIGH8.1Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL enviro...
CVE-2020-15852HIGH7.8An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attac...
CVE-2020-3481HIGH7.5A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could a...
CVE-2020-15052HIGH7.5An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alia...
CVE-2020-8214HIGH7.5A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file.
CVE-2020-12031HIGH7.8In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a lo...
CVE-2020-12028HIGH8.1In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to int...
CVE-2020-8215HIGH8.8A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitra...
CVE-2020-8205HIGH7.5The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, w...
CVE-2020-12029HIGH7.8All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, un...
CVE-2020-15009HIGH7.8AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs ...
CVE-2020-15842HIGH8.1Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, ...
CVE-2020-15841HIGH8.8Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, ...
CVE-2020-9257HIGH8.8HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C...
CVE-2020-9254HIGH7.8HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now