2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-16014CRITICAL9.6Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the rendere...
CVE-2020-16013HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially expl...
CVE-2020-16012MEDIUM4.3Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cr...
CVE-2020-28208MEDIUM5.3An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
CVE-2020-26664HIGH7.8A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based...
CVE-2020-25678MEDIUM4.4A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be f...
CVE-2020-17504HIGH7.2The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that w...
CVE-2020-17503HIGH7.2The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that w...
CVE-2020-17502HIGH7.2Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which i...
CVE-2020-35131CRITICAL9.8Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCrite...
CVE-2020-8584CRITICAL9.8Element OS versions prior to 1.8P1 and 12.2 are susceptible to a vulnerability that could allow an unauthenticated remot...
CVE-2020-5805HIGH8.8In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on ...
CVE-2020-5804HIGH8.1Marvell QConvergeConsole GUI <= 5.5.0.74 is affected by a path traversal vulnerability. The deleteEventLogFile method of...
CVE-2020-27262MEDIUM5.4Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 A stored cross-site scripting (XSS) vulnerability ex...
CVE-2020-27260MEDIUM5.3Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affe...
CVE-2020-4667MEDIUM4.3IBM Engineering Requirements Quality Assistant On-Premises could allow an authenticated user to obtain sensitive informa...
CVE-2020-4666MEDIUM5.4IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability all...
CVE-2020-4664MEDIUM5.4IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability all...
CVE-2020-4663MEDIUM5.4IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability all...
CVE-2020-4606MEDIUM4.4IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processin...
CVE-2020-7794CRITICAL9.8This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the ...
CVE-2020-7784CRITICAL9.8This affects all versions of package ts-process-promises. The injection point is located in line 45 in main entry of pac...
CVE-2020-28468CRITICAL9.8This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulner...
CVE-2020-25950MEDIUM4.3Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact...
CVE-2020-24577HIGH7.5An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch applicatio...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now