2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-9800HIGH8.8A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvO...
CVE-2020-9795HIGH7.8A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.5 and iPadOS 13.5, m...
CVE-2020-9794HIGH8.1An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macO...
CVE-2020-9793HIGH7.8A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5,...
CVE-2020-9791HIGH7.8An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, mac...
CVE-2020-9790HIGH8.8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13....
CVE-2020-9789HIGH8.8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13....
CVE-2020-9788HIGH7.8A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.5. A file...
CVE-2020-13978HIGH7.2Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk...
CVE-2020-13976HIGH8.8An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary comman...
CVE-2020-10757HIGH7.8A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allow...
CVE-2020-5589HIGH8.8SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X...
CVE-2020-13974HIGH7.8An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_as...
CVE-2020-13962HIGH7.5Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error qu...
CVE-2020-4038HIGH7.4GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulne...
CVE-2020-13960HIGH7.5D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search p...
CVE-2020-13885HIGH7.8Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during ...
CVE-2020-13884HIGH7.8Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows loc...
CVE-2020-13428HIGH7.8A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media p...
CVE-2020-13432HIGH7.5rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to ...
CVE-2020-5304HIGH7.5The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a...
CVE-2020-13625HIGH7.5PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote charac...
CVE-2020-12695HIGH7.5The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription r...
CVE-2020-9042HIGH8.8In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has us...
CVE-2020-9041HIGH7.5In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now