2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8187 | HIGH | 7.5 | 1.9% | Jul 10, 2020 | Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticat... |
| CVE-2020-3974 | HIGH | 7.8 | 0.4% | Jul 10, 2020 | VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for... |
| CVE-2020-4305 | HIGH | 8.8 | 4.5% | Jul 9, 2020 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the sy... |
| CVE-2020-15093 | HIGH | 8.6 | 1.4% | Jul 9, 2020 | The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signat... |
| CVE-2020-13994 | HIGH | 8.8 | 7.4% | Jul 9, 2020 | An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the ser... |
| CVE-2020-13993 | HIGH | 7.5 | 2.1% | Jul 9, 2020 | An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A blind time-based SQL injection issue allows remote un... |
| CVE-2020-12426 | HIGH | 8.8 | 1.6% | Jul 9, 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed ev... |
| CVE-2020-12423 | HIGH | 7.8 | 0.4% | Jul 9, 2020 | When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in... |
| CVE-2020-12422 | HIGH | 8.8 | 1.9% | Jul 9, 2020 | In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, r... |
| CVE-2020-12420 | HIGH | 8.8 | 1.9% | Jul 9, 2020 | When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to me... |
| CVE-2020-12419 | HIGH | 8.8 | 2.3% | Jul 9, 2020 | When processing callbacks that occurred during window flushing in the parent process, the associated window may die; cau... |
| CVE-2020-12417 | HIGH | 8.8 | 2.7% | Jul 9, 2020 | Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory... |
| CVE-2020-12416 | HIGH | 8.8 | 1.4% | Jul 9, 2020 | A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-... |
| CVE-2020-12411 | HIGH | 8.8 | 1.2% | Jul 9, 2020 | Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corru... |
| CVE-2020-12410 | HIGH | 8.8 | 1.5% | Jul 9, 2020 | Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evi... |
| CVE-2020-12409 | HIGH | 8.8 | 1.0% | Jul 9, 2020 | When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This ... |
| CVE-2020-12406 | HIGH | 8.8 | 1.0% | Jul 9, 2020 | Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We ... |
| CVE-2020-12398 | HIGH | 7.5 | 1.0% | Jul 9, 2020 | If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbi... |
| CVE-2020-7457 | HIGH | 8.1 | 33.0% | Jul 9, 2020 | In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 1... |
| CVE-2020-9377 | HIGH | 8.8 | 21.3% | Jul 9, 2020 | D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability onl... |
| CVE-2020-9376 | HIGH | 7.5 | 16.6% | Jul 9, 2020 | D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE... |
| CVE-2020-5604 | HIGH | 8.1 | 2.0% | Jul 9, 2020 | Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a re... |
| CVE-2020-5974 | HIGH | 7.8 | 0.3% | Jul 8, 2020 | NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are i... |
| CVE-2020-15072 | HIGH | 8.8 | 1.2% | Jul 8, 2020 | An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Admin... |
| CVE-2020-2034 | HIGH | 8.1 | 6.6% | Jul 8, 2020 | An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacke... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now