2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26962MEDIUM6.1Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated...
CVE-2020-26961MEDIUM6.5When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not...
CVE-2020-26960HIGH8.8If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers...
CVE-2020-26959HIGH8.8During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-afte...
CVE-2020-26958MEDIUM6.1Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached throug...
CVE-2020-26957MEDIUM6.5OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a...
CVE-2020-26956MEDIUM6.1In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to X...
CVE-2020-26955MEDIUM6.5When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent...
CVE-2020-26954MEDIUM4.3When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file ...
CVE-2020-26953MEDIUM4.3It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possibl...
CVE-2020-26952HIGH8.8Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruption and a potentially ...
CVE-2020-26951MEDIUM6.1A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitizati...
CVE-2020-26950HIGH8.8In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable ...
CVE-2020-25627MEDIUM6.1The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3....
CVE-2020-10146MEDIUM5.4The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter tha...
CVE-2020-27614HIGH7.8AnyDesk for macOS versions 6.0.2 and older have a vulnerability in the XPC interface that does not properly validate cli...
CVE-2020-26249HIGH8.7Red Discord Bot Dashboard is an easy-to-use interactive web dashboard to control your Redbot. In Red Discord Bot before ...
CVE-2020-26234MEDIUM4.8Opencast before versions 8.9 and 7.9 disables HTTPS hostname verification of its HTTP client used for a large portion of...
CVE-2020-9991HIGH7.5This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iP...
CVE-2020-28274CRITICAL9.8Prototype pollution vulnerability in 'deepref' versions 1.1.1 through 1.2.1 allows attacker to cause a denial of service...
CVE-2020-27918HIGH7.8A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watch...
CVE-2020-27896MEDIUM5.5A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1. A remote atta...
CVE-2020-27821MEDIUM6A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue cou...
CVE-2020-27758LOW3.3A flaw was found in ImageMagick in coders/txt.c. An attacker who submits a crafted file that is processed by ImageMagick...
CVE-2020-27757LOW3.3A floating point math calculation in ScaleAnyToQuantum() of /MagickCore/quantum-private.h could lead to undefined behavi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now