2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-6442MEDIUM4.3Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-ori...
CVE-2020-6441MEDIUM4.3Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass se...
CVE-2020-6440MEDIUM4.3Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a us...
CVE-2020-6438MEDIUM4.3Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a...
CVE-2020-6437MEDIUM4.3Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof securi...
CVE-2020-6435MEDIUM4.3Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had c...
CVE-2020-6433MEDIUM4.3Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass...
CVE-2020-6432MEDIUM4.3Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypas...
CVE-2020-6431MEDIUM4.3Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof...
CVE-2020-11734MEDIUM6.1cgi-bin/go in CyberSolutions CyberMail 5 or later allows XSS via the ACTION parameter.
CVE-2020-8430MEDIUM6.1Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive ...
CVE-2020-8148MEDIUM5.3UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostnam...
CVE-2020-1759MEDIUM6.8A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vul...
CVE-2020-11731MEDIUM6.1The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/M...
CVE-2020-11721MEDIUM6.5load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, wh...
CVE-2020-11714MEDIUM5.4eten PSG-6528VM 1.1 devices allow XSS via System Contact or System Location.
CVE-2020-11712MEDIUM6.1Open Upload through 0.4.3 allows XSS via index.php?action=u and the filename field.
CVE-2020-11704MEDIUM6.1An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and R...
CVE-2020-11702MEDIUM6.1An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The User Web Interface has Multiple Stored and Re...
CVE-2020-9056MEDIUM5.4Periscope BuySpeed version 14.5 is vulnerable to stored cross-site scripting, which could allow a local, authenticated a...
CVE-2020-5406MEDIUM6.5VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x vers...
CVE-2020-1801MEDIUM5.5There is an improper authentication vulnerability in several smartphones. Certain function interface in the system does ...
CVE-2020-11669MEDIUM5.5An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does n...
CVE-2020-1802MEDIUM4.6There is an insufficient integrity validation vulnerability in several products. The device does not sufficiently valida...
CVE-2020-8832MEDIUM5.5The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data struc...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now