2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6451 | HIGH | 8.8 | 1.5% | Apr 13, 2020 | Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap... |
| CVE-2020-6450 | HIGH | 8.8 | 1.5% | Apr 13, 2020 | Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap... |
| CVE-2020-6448 | HIGH | 8.8 | 1.7% | Apr 13, 2020 | Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corrup... |
| CVE-2020-6447 | HIGH | 8.8 | 1.8% | Apr 13, 2020 | Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had... |
| CVE-2020-6443 | HIGH | 8.8 | 1.8% | Apr 13, 2020 | Insufficient data validation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had... |
| CVE-2020-6439 | HIGH | 8.8 | 1.8% | Apr 13, 2020 | Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypas... |
| CVE-2020-6436 | HIGH | 8.8 | 1.6% | Apr 13, 2020 | Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially expl... |
| CVE-2020-6434 | HIGH | 8.8 | 1.7% | Apr 13, 2020 | Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap ... |
| CVE-2020-6430 | HIGH | 8.8 | 1.9% | Apr 13, 2020 | Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corrup... |
| CVE-2020-6423 | HIGH | 8.8 | 1.7% | Apr 13, 2020 | Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2020-9478 | HIGH | 8.8 | 3.1% | Apr 13, 2020 | An issue was discovered in Rubrik 5.0.3-2296. An OS command injection vulnerability allows an authenticated attacker to ... |
| CVE-2020-11732 | HIGH | 7.5 | 4.9% | Apr 13, 2020 | The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_ga... |
| CVE-2020-11725 | HIGH | 7.8 | 0.5% | Apr 12, 2020 | snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner line, which later aff... |
| CVE-2020-11724 | HIGH | 7.5 | 2.6% | Apr 12, 2020 | An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demons... |
| CVE-2020-11713 | HIGH | 7.5 | 2.0% | Apr 12, 2020 | wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properly resist timing side-channel attacks. |
| CVE-2020-11709 | HIGH | 7.5 | 1.6% | Apr 12, 2020 | cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, whic... |
| CVE-2020-11707 | HIGH | 8.8 | 1.0% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlin... |
| CVE-2020-11706 | HIGH | 8.8 | 0.5% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Interface allows CSRF for actions such ... |
| CVE-2020-11703 | HIGH | 7.5 | 0.9% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response... |
| CVE-2020-11701 | HIGH | 8.8 | 0.5% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. CSRF exists in the User Web Interface, as demonst... |
| CVE-2020-11694 | HIGH | 7.5 | 1.8% | Apr 10, 2020 | In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed... |
| CVE-2020-11647 | HIGH | 7.5 | 3.3% | Apr 10, 2020 | In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed i... |
| CVE-2020-6765 | HIGH | 7.2 | 1.2% | Apr 10, 2020 | D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after a suppo... |
| CVE-2020-5330 | HIGH | 7.5 | 12.9% | Apr 10, 2020 | Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 ... |
| CVE-2020-11002 | HIGH | 8.8 | 5.2% | Apr 10, 2020 | dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now