2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-6451HIGH8.8Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap...
CVE-2020-6450HIGH8.8Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap...
CVE-2020-6448HIGH8.8Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corrup...
CVE-2020-6447HIGH8.8Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had...
CVE-2020-6443HIGH8.8Insufficient data validation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had...
CVE-2020-6439HIGH8.8Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypas...
CVE-2020-6436HIGH8.8Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially expl...
CVE-2020-6434HIGH8.8Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap ...
CVE-2020-6430HIGH8.8Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corrup...
CVE-2020-6423HIGH8.8Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap cor...
CVE-2020-9478HIGH8.8An issue was discovered in Rubrik 5.0.3-2296. An OS command injection vulnerability allows an authenticated attacker to ...
CVE-2020-11732HIGH7.5The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_ga...
CVE-2020-11725HIGH7.8snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner line, which later aff...
CVE-2020-11724HIGH7.5An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demons...
CVE-2020-11713HIGH7.5wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properly resist timing side-channel attacks.
CVE-2020-11709HIGH7.5cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, whic...
CVE-2020-11707HIGH8.8An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlin...
CVE-2020-11706HIGH8.8An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Interface allows CSRF for actions such ...
CVE-2020-11703HIGH7.5An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response...
CVE-2020-11701HIGH8.8An issue was discovered in ProVide (formerly zFTPServer) through 13.1. CSRF exists in the User Web Interface, as demonst...
CVE-2020-11694HIGH7.5In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed...
CVE-2020-11647HIGH7.5In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed i...
CVE-2020-6765HIGH7.2D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after a suppo...
CVE-2020-5330HIGH7.5Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 ...
CVE-2020-11002HIGH8.8dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now