2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-8187HIGH7.5Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticat...
CVE-2020-3974HIGH7.8VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for...
CVE-2020-4305HIGH8.8IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the sy...
CVE-2020-15093HIGH8.6The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signat...
CVE-2020-13994HIGH8.8An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the ser...
CVE-2020-13993HIGH7.5An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A blind time-based SQL injection issue allows remote un...
CVE-2020-12426HIGH8.8Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed ev...
CVE-2020-12423HIGH7.8When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in...
CVE-2020-12422HIGH8.8In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, r...
CVE-2020-12420HIGH8.8When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to me...
CVE-2020-12419HIGH8.8When processing callbacks that occurred during window flushing in the parent process, the associated window may die; cau...
CVE-2020-12417HIGH8.8Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory...
CVE-2020-12416HIGH8.8A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-...
CVE-2020-12411HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corru...
CVE-2020-12410HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evi...
CVE-2020-12409HIGH8.8When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This ...
CVE-2020-12406HIGH8.8Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We ...
CVE-2020-12398HIGH7.5If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbi...
CVE-2020-7457HIGH8.1In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 1...
CVE-2020-9377HIGH8.8D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability onl...
CVE-2020-9376HIGH7.5D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE...
CVE-2020-5604HIGH8.1Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a re...
CVE-2020-5974HIGH7.8NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are i...
CVE-2020-15072HIGH8.8An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Admin...
CVE-2020-2034HIGH8.1An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacke...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now