2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6480 | MEDIUM | 6.5 | 1.2% | May 21, 2020 | Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass ... |
| CVE-2020-6479 | MEDIUM | 6.5 | 1.6% | May 21, 2020 | Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof securi... |
| CVE-2020-6478 | MEDIUM | 6.5 | 1.6% | May 21, 2020 | Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof se... |
| CVE-2020-6476 | MEDIUM | 6.5 | 1.3% | May 21, 2020 | Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a ... |
| CVE-2020-6475 | MEDIUM | 6.5 | 1.7% | May 21, 2020 | Incorrect implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof securi... |
| CVE-2020-6473 | MEDIUM | 6.5 | 1.8% | May 21, 2020 | Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain pote... |
| CVE-2020-6472 | MEDIUM | 6.5 | 1.5% | May 21, 2020 | Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convin... |
| CVE-2020-6470 | MEDIUM | 6.1 | 1.0% | May 21, 2020 | Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker ... |
| CVE-2020-6460 | MEDIUM | 6.5 | 0.9% | May 21, 2020 | Insufficient data validation in URL formatting in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to perf... |
| CVE-2020-11078 | MEDIUM | 6.8 | 2.6% | May 20, 2020 | In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could cha... |
| CVE-2020-13240 | MEDIUM | 5.4 | 0.7% | May 20, 2020 | The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded ... |
| CVE-2020-13239 | MEDIUM | 5.4 | 0.7% | May 20, 2020 | The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is ... |
| CVE-2020-5753 | MEDIUM | 5.3 | 1.1% | May 20, 2020 | Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's S... |
| CVE-2020-13231 | MEDIUM | 6.5 | 0.8% | May 20, 2020 | In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change. |
| CVE-2020-13230 | MEDIUM | 4.3 | 1.0% | May 20, 2020 | In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account... |
| CVE-2020-10726 | MEDIUM | 4.4 | 0.5% | May 20, 2020 | A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-us... |
| CVE-2020-4461 | MEDIUM | 6.5 | 0.9% | May 20, 2020 | IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security by allowing id_token ... |
| CVE-2020-13152 | MEDIUM | 5.5 | 3.4% | May 20, 2020 | A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will tri... |
| CVE-2020-13225 | MEDIUM | 4.8 | 0.6% | May 20, 2020 | phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the Us... |
| CVE-2020-7137 | MEDIUM | 6.7 | 0.3% | May 19, 2020 | A validation issue in HPE Superdome Flex's RMC component may allow local elevation of privilege. Apply HPE Superdome Fle... |
| CVE-2020-12038 | MEDIUM | 5.5 | 2.5% | May 19, 2020 | Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterpris... |
| CVE-2020-7656 | MEDIUM | 6.1 | 6.3% | May 19, 2020 | jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and re... |
| CVE-2020-2024 | MEDIUM | 6.5 | 0.4% | May 19, 2020 | An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a m... |
| CVE-2020-10724 | MEDIUM | 4.4 | 0.4% | May 19, 2020 | A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for use... |
| CVE-2020-10723 | MEDIUM | 6.7 | 0.4% | May 19, 2020 | A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on th... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now