2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-6480MEDIUM6.5Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass ...
CVE-2020-6479MEDIUM6.5Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof securi...
CVE-2020-6478MEDIUM6.5Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof se...
CVE-2020-6476MEDIUM6.5Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a ...
CVE-2020-6475MEDIUM6.5Incorrect implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof securi...
CVE-2020-6473MEDIUM6.5Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain pote...
CVE-2020-6472MEDIUM6.5Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convin...
CVE-2020-6470MEDIUM6.1Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker ...
CVE-2020-6460MEDIUM6.5Insufficient data validation in URL formatting in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to perf...
CVE-2020-11078MEDIUM6.8In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could cha...
CVE-2020-13240MEDIUM5.4The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded ...
CVE-2020-13239MEDIUM5.4The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is ...
CVE-2020-5753MEDIUM5.3Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's S...
CVE-2020-13231MEDIUM6.5In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.
CVE-2020-13230MEDIUM4.3In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account...
CVE-2020-10726MEDIUM4.4A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-us...
CVE-2020-4461MEDIUM6.5IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security by allowing id_token ...
CVE-2020-13152MEDIUM5.5A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will tri...
CVE-2020-13225MEDIUM4.8phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the Us...
CVE-2020-7137MEDIUM6.7A validation issue in HPE Superdome Flex's RMC component may allow local elevation of privilege. Apply HPE Superdome Fle...
CVE-2020-12038MEDIUM5.5Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterpris...
CVE-2020-7656MEDIUM6.1jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and re...
CVE-2020-2024MEDIUM6.5An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a m...
CVE-2020-10724MEDIUM4.4A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for use...
CVE-2020-10723MEDIUM6.7A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on th...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now