2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5607 | MEDIUM | 6.1 | 1.2% | Jul 10, 2020 | Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web ... |
| CVE-2020-4173 | MEDIUM | 4.3 | 0.9% | Jul 9, 2020 | IBM Guardium Activity Insights 10.6 and 11.0 does not set the secure attribute on authorization tokens or session cookie... |
| CVE-2020-15299 | MEDIUM | 6.1 | 47.0% | Jul 9, 2020 | A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remot... |
| CVE-2020-15092 | MEDIUM | 4.8 | 1.1% | Jul 9, 2020 | In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with mali... |
| CVE-2020-15001 | MEDIUM | 5.3 | 0.6% | Jul 9, 2020 | An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP applicatio... |
| CVE-2020-15000 | MEDIUM | 5.9 | 0.7% | Jul 9, 2020 | A PIN management problem was discovered on Yubico YubiKey 5 devices 5.2.0 to 5.2.6. OpenPGP has three passwords: Admin P... |
| CVE-2020-14171 | MEDIUM | 6.5 | 0.6% | Jul 9, 2020 | Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repo... |
| CVE-2020-14170 | MEDIUM | 4.3 | 0.8% | Jul 9, 2020 | Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the cont... |
| CVE-2020-13132 | MEDIUM | 4.6 | 0.6% | Jul 9, 2020 | An issue was discovered in Yubico libykpiv before 2.1.0. An attacker can trigger an incorrect free() in the ykpiv_util_g... |
| CVE-2020-13131 | MEDIUM | 4.3 | 0.5% | Jul 9, 2020 | An issue was discovered in Yubico libykpiv before 2.1.0. lib/util.c in this library (which is included in yubico-piv-too... |
| CVE-2020-15526 | MEDIUM | 5.9 | 0.5% | Jul 9, 2020 | In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks ca... |
| CVE-2020-10756 | MEDIUM | 6.5 | 0.5% | Jul 9, 2020 | An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occ... |
| CVE-2020-13992 | MEDIUM | 6.1 | 1.2% | Jul 9, 2020 | An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A Stored XSS issue allows remote unauthenticated attack... |
| CVE-2020-12425 | MEDIUM | 6.5 | 1.4% | Jul 9, 2020 | Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leadi... |
| CVE-2020-12421 | MEDIUM | 6.5 | 1.8% | Jul 9, 2020 | When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were le... |
| CVE-2020-12418 | MEDIUM | 6.5 | 3.0% | Jul 9, 2020 | Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicio... |
| CVE-2020-12415 | MEDIUM | 6.5 | 1.3% | Jul 9, 2020 | When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to... |
| CVE-2020-12414 | MEDIUM | 6.5 | 0.7% | Jul 9, 2020 | IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was bei... |
| CVE-2020-12412 | MEDIUM | 4.3 | 0.8% | Jul 9, 2020 | By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with... |
| CVE-2020-12408 | MEDIUM | 6.5 | 0.8% | Jul 9, 2020 | When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path in... |
| CVE-2020-12407 | MEDIUM | 6.5 | 1.0% | Jul 9, 2020 | Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary G... |
| CVE-2020-12405 | MEDIUM | 5.3 | 1.4% | Jul 9, 2020 | When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploi... |
| CVE-2020-12404 | MEDIUM | 4.3 | 0.8% | Jul 9, 2020 | For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging... |
| CVE-2020-12402 | MEDIUM | 4.4 | 0.3% | Jul 9, 2020 | During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which enta... |
| CVE-2020-12399 | MEDIUM | 4.4 | 0.7% | Jul 9, 2020 | NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now