2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6442 | MEDIUM | 4.3 | 1.9% | Apr 13, 2020 | Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-ori... |
| CVE-2020-6441 | MEDIUM | 4.3 | 1.7% | Apr 13, 2020 | Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass se... |
| CVE-2020-6440 | MEDIUM | 4.3 | 1.2% | Apr 13, 2020 | Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a us... |
| CVE-2020-6438 | MEDIUM | 4.3 | 1.3% | Apr 13, 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a... |
| CVE-2020-6437 | MEDIUM | 4.3 | 1.7% | Apr 13, 2020 | Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof securi... |
| CVE-2020-6435 | MEDIUM | 4.3 | 1.6% | Apr 13, 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had c... |
| CVE-2020-6433 | MEDIUM | 4.3 | 1.6% | Apr 13, 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass... |
| CVE-2020-6432 | MEDIUM | 4.3 | 1.7% | Apr 13, 2020 | Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypas... |
| CVE-2020-6431 | MEDIUM | 4.3 | 1.5% | Apr 13, 2020 | Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof... |
| CVE-2020-11734 | MEDIUM | 6.1 | 1.0% | Apr 13, 2020 | cgi-bin/go in CyberSolutions CyberMail 5 or later allows XSS via the ACTION parameter. |
| CVE-2020-8430 | MEDIUM | 6.1 | 0.9% | Apr 13, 2020 | Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive ... |
| CVE-2020-8148 | MEDIUM | 5.3 | 1.0% | Apr 13, 2020 | UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostnam... |
| CVE-2020-1759 | MEDIUM | 6.8 | 1.4% | Apr 13, 2020 | A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vul... |
| CVE-2020-11731 | MEDIUM | 6.1 | 1.2% | Apr 13, 2020 | The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/M... |
| CVE-2020-11721 | MEDIUM | 6.5 | 0.9% | Apr 12, 2020 | load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, wh... |
| CVE-2020-11714 | MEDIUM | 5.4 | 0.7% | Apr 12, 2020 | eten PSG-6528VM 1.1 devices allow XSS via System Contact or System Location. |
| CVE-2020-11712 | MEDIUM | 6.1 | 1.1% | Apr 12, 2020 | Open Upload through 0.4.3 allows XSS via index.php?action=u and the filename field. |
| CVE-2020-11704 | MEDIUM | 6.1 | 0.7% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and R... |
| CVE-2020-11702 | MEDIUM | 6.1 | 0.7% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The User Web Interface has Multiple Stored and Re... |
| CVE-2020-9056 | MEDIUM | 5.4 | 0.6% | Apr 10, 2020 | Periscope BuySpeed version 14.5 is vulnerable to stored cross-site scripting, which could allow a local, authenticated a... |
| CVE-2020-5406 | MEDIUM | 6.5 | 1.0% | Apr 10, 2020 | VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x vers... |
| CVE-2020-1801 | MEDIUM | 5.5 | 0.6% | Apr 10, 2020 | There is an improper authentication vulnerability in several smartphones. Certain function interface in the system does ... |
| CVE-2020-11669 | MEDIUM | 5.5 | 0.5% | Apr 10, 2020 | An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does n... |
| CVE-2020-1802 | MEDIUM | 4.6 | 0.1% | Apr 10, 2020 | There is an insufficient integrity validation vulnerability in several products. The device does not sufficiently valida... |
| CVE-2020-8832 | MEDIUM | 5.5 | 0.5% | Apr 10, 2020 | The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data struc... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now