2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35111MEDIUM4.3When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not trigg...
CVE-2020-26979MEDIUM6.1When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes ca...
CVE-2020-26978MEDIUM6.1Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network'...
CVE-2020-26977MEDIUM6.5By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab wh...
CVE-2020-26976MEDIUM6.5When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service wo...
CVE-2020-26975MEDIUM6.5When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary header...
CVE-2020-26974HIGH8.8When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wron...
CVE-2020-26973HIGH8.8Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been us...
CVE-2020-26972CRITICAL9.8The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they ...
CVE-2020-26971HIGH8.8Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video d...
CVE-2020-26768MEDIUM6.1Formstone <=1.4.16 is vulnerable to a Reflected Cross-Site Scripting (XSS) vulnerability caused by improper validation o...
CVE-2020-24903MEDIUM6.1Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user ...
CVE-2020-24902MEDIUM6.1Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied ...
CVE-2020-24901MEDIUM6.1The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remot...
CVE-2020-24900MEDIUM6.1The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load i...
CVE-2020-36183HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-36182HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-36180HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-36179HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-26085CRITICAL9.9Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a...
CVE-2020-36189HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-36188HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-36187HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-36186HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-36185HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now