2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6399 | MEDIUM | 6.5 | 2.0% | Feb 11, 2020 | Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cro... |
| CVE-2020-6397 | MEDIUM | 6.5 | 1.9% | Feb 11, 2020 | Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof securi... |
| CVE-2020-6396 | MEDIUM | 4.3 | 1.7% | Feb 11, 2020 | Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the conte... |
| CVE-2020-6395 | MEDIUM | 6.5 | 2.0% | Feb 11, 2020 | Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially ... |
| CVE-2020-6394 | MEDIUM | 5.4 | 1.7% | Feb 11, 2020 | Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass cont... |
| CVE-2020-6393 | MEDIUM | 6.5 | 1.9% | Feb 11, 2020 | Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-... |
| CVE-2020-6392 | MEDIUM | 4.3 | 1.5% | Feb 11, 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a... |
| CVE-2020-6391 | MEDIUM | 4.3 | 1.3% | Feb 11, 2020 | Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to b... |
| CVE-2020-3933 | MEDIUM | 5.3 | 1.2% | Feb 11, 2020 | TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, allows attackers to enumerate ... |
| CVE-2020-8089 | MEDIUM | 5.4 | 0.6% | Feb 10, 2020 | Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page. |
| CVE-2020-1697 | MEDIUM | 5.4 | 0.8% | Feb 10, 2020 | It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin ... |
| CVE-2020-8825 | MEDIUM | 5.4 | 1.9% | Feb 10, 2020 | index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS. |
| CVE-2020-8823 | MEDIUM | 6.1 | 1.8% | Feb 10, 2020 | htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka cal... |
| CVE-2020-8822 | MEDIUM | 4.8 | 0.6% | Feb 10, 2020 | Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices allow stored XSS in the web application. |
| CVE-2020-8812 | MEDIUM | 5.4 | 0.6% | Feb 7, 2020 | Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's per... |
| CVE-2020-8811 | MEDIUM | 4.3 | 0.5% | Feb 7, 2020 | ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures. |
| CVE-2020-1700 | MEDIUM | 6.5 | 2.5% | Feb 7, 2020 | A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can a... |
| CVE-2020-1768 | MEDIUM | 5.4 | 0.7% | Feb 7, 2020 | The external frontend system uses numerous background calls to the backend. Each background request is treated as user a... |
| CVE-2020-8788 | MEDIUM | 6.1 | 0.8% | Feb 7, 2020 | Synaptive Medical ClearCanvas ImageServer 3.0 Alpha allows XSS (and HTML injection) via the Default.aspx UserName parame... |
| CVE-2020-5317 | MEDIUM | 4.8 | 0.6% | Feb 6, 2020 | Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user could exploit... |
| CVE-2020-8608 | MEDIUM | 5.6 | 2.5% | Feb 6, 2020 | In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in lat... |
| CVE-2020-6856 | MEDIUM | 6.5 | 0.9% | Feb 6, 2020 | An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allow... |
| CVE-2020-6855 | MEDIUM | 6.5 | 0.9% | Feb 6, 2020 | A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers... |
| CVE-2020-6767 | MEDIUM | 6.5 | 1.3% | Feb 6, 2020 | A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated r... |
| CVE-2020-5720 | MEDIUM | 5.9 | 1.1% | Feb 6, 2020 | MikroTik WinBox before 3.21 is vulnerable to a path traversal vulnerability that allows creation of arbitrary files wher... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now