2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35111 | MEDIUM | 4.3 | 1.2% | Jan 7, 2021 | When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not trigg... |
| CVE-2020-26979 | MEDIUM | 6.1 | 0.7% | Jan 7, 2021 | When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes ca... |
| CVE-2020-26978 | MEDIUM | 6.1 | 1.3% | Jan 7, 2021 | Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network'... |
| CVE-2020-26977 | MEDIUM | 6.5 | 0.9% | Jan 7, 2021 | By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab wh... |
| CVE-2020-26976 | MEDIUM | 6.5 | 1.6% | Jan 7, 2021 | When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service wo... |
| CVE-2020-26975 | MEDIUM | 6.5 | 0.9% | Jan 7, 2021 | When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary header... |
| CVE-2020-26974 | HIGH | 8.8 | 1.5% | Jan 7, 2021 | When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wron... |
| CVE-2020-26973 | HIGH | 8.8 | 1.6% | Jan 7, 2021 | Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been us... |
| CVE-2020-26972 | CRITICAL | 9.8 | 1.3% | Jan 7, 2021 | The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they ... |
| CVE-2020-26971 | HIGH | 8.8 | 1.9% | Jan 7, 2021 | Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video d... |
| CVE-2020-26768 | MEDIUM | 6.1 | 1.2% | Jan 7, 2021 | Formstone <=1.4.16 is vulnerable to a Reflected Cross-Site Scripting (XSS) vulnerability caused by improper validation o... |
| CVE-2020-24903 | MEDIUM | 6.1 | 2.9% | Jan 7, 2021 | Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user ... |
| CVE-2020-24902 | MEDIUM | 6.1 | 2.9% | Jan 7, 2021 | Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied ... |
| CVE-2020-24901 | MEDIUM | 6.1 | 1.0% | Jan 7, 2021 | The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remot... |
| CVE-2020-24900 | MEDIUM | 6.1 | 0.9% | Jan 7, 2021 | The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load i... |
| CVE-2020-36183 | HIGH | 8.1 | 4.9% | Jan 7, 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-36182 | HIGH | 8.1 | 5.0% | Jan 7, 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-36180 | HIGH | 8.1 | 5.0% | Jan 7, 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-36179 | HIGH | 8.1 | 20.9% | Jan 7, 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-26085 | CRITICAL | 9.9 | 2.5% | Jan 7, 2021 | Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a... |
| CVE-2020-36189 | HIGH | 8.1 | 4.9% | Jan 6, 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-36188 | HIGH | 8.1 | 10.9% | Jan 6, 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-36187 | HIGH | 8.1 | 5.2% | Jan 6, 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-36186 | HIGH | 8.1 | 5.2% | Jan 6, 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-36185 | HIGH | 8.1 | 5.2% | Jan 6, 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now