2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-5607MEDIUM6.1Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web ...
CVE-2020-4173MEDIUM4.3IBM Guardium Activity Insights 10.6 and 11.0 does not set the secure attribute on authorization tokens or session cookie...
CVE-2020-15299MEDIUM6.1A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remot...
CVE-2020-15092MEDIUM4.8In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with mali...
CVE-2020-15001MEDIUM5.3An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP applicatio...
CVE-2020-15000MEDIUM5.9A PIN management problem was discovered on Yubico YubiKey 5 devices 5.2.0 to 5.2.6. OpenPGP has three passwords: Admin P...
CVE-2020-14171MEDIUM6.5Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repo...
CVE-2020-14170MEDIUM4.3Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the cont...
CVE-2020-13132MEDIUM4.6An issue was discovered in Yubico libykpiv before 2.1.0. An attacker can trigger an incorrect free() in the ykpiv_util_g...
CVE-2020-13131MEDIUM4.3An issue was discovered in Yubico libykpiv before 2.1.0. lib/util.c in this library (which is included in yubico-piv-too...
CVE-2020-15526MEDIUM5.9In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks ca...
CVE-2020-10756MEDIUM6.5An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occ...
CVE-2020-13992MEDIUM6.1An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A Stored XSS issue allows remote unauthenticated attack...
CVE-2020-12425MEDIUM6.5Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leadi...
CVE-2020-12421MEDIUM6.5When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were le...
CVE-2020-12418MEDIUM6.5Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicio...
CVE-2020-12415MEDIUM6.5When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to...
CVE-2020-12414MEDIUM6.5IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was bei...
CVE-2020-12412MEDIUM4.3By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with...
CVE-2020-12408MEDIUM6.5When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path in...
CVE-2020-12407MEDIUM6.5Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary G...
CVE-2020-12405MEDIUM5.3When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploi...
CVE-2020-12404MEDIUM4.3For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging...
CVE-2020-12402MEDIUM4.4During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which enta...
CVE-2020-12399MEDIUM4.4NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now