2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26962 | MEDIUM | 6.1 | 0.7% | Dec 9, 2020 | Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated... |
| CVE-2020-26961 | MEDIUM | 6.5 | 1.2% | Dec 9, 2020 | When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not... |
| CVE-2020-26960 | HIGH | 8.8 | 1.6% | Dec 9, 2020 | If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers... |
| CVE-2020-26959 | HIGH | 8.8 | 1.3% | Dec 9, 2020 | During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-afte... |
| CVE-2020-26958 | MEDIUM | 6.1 | 1.3% | Dec 9, 2020 | Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached throug... |
| CVE-2020-26957 | MEDIUM | 6.5 | 0.5% | Dec 9, 2020 | OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a... |
| CVE-2020-26956 | MEDIUM | 6.1 | 1.2% | Dec 9, 2020 | In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to X... |
| CVE-2020-26955 | MEDIUM | 6.5 | 0.8% | Dec 9, 2020 | When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent... |
| CVE-2020-26954 | MEDIUM | 4.3 | 0.6% | Dec 9, 2020 | When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file ... |
| CVE-2020-26953 | MEDIUM | 4.3 | 1.3% | Dec 9, 2020 | It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possibl... |
| CVE-2020-26952 | HIGH | 8.8 | 1.2% | Dec 9, 2020 | Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruption and a potentially ... |
| CVE-2020-26951 | MEDIUM | 6.1 | 1.0% | Dec 9, 2020 | A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitizati... |
| CVE-2020-26950 | HIGH | 8.8 | 42.6% | Dec 9, 2020 | In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable ... |
| CVE-2020-25627 | MEDIUM | 6.1 | 3.7% | Dec 9, 2020 | The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.... |
| CVE-2020-10146 | MEDIUM | 5.4 | 1.9% | Dec 9, 2020 | The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter tha... |
| CVE-2020-27614 | HIGH | 7.8 | 0.3% | Dec 9, 2020 | AnyDesk for macOS versions 6.0.2 and older have a vulnerability in the XPC interface that does not properly validate cli... |
| CVE-2020-26249 | HIGH | 8.7 | 1.1% | Dec 9, 2020 | Red Discord Bot Dashboard is an easy-to-use interactive web dashboard to control your Redbot. In Red Discord Bot before ... |
| CVE-2020-26234 | MEDIUM | 4.8 | 0.3% | Dec 8, 2020 | Opencast before versions 8.9 and 7.9 disables HTTPS hostname verification of its HTTP client used for a large portion of... |
| CVE-2020-9991 | HIGH | 7.5 | 2.8% | Dec 8, 2020 | This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iP... |
| CVE-2020-28274 | CRITICAL | 9.8 | 2.2% | Dec 8, 2020 | Prototype pollution vulnerability in 'deepref' versions 1.1.1 through 1.2.1 allows attacker to cause a denial of service... |
| CVE-2020-27918 | HIGH | 7.8 | 1.4% | Dec 8, 2020 | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watch... |
| CVE-2020-27896 | MEDIUM | 5.5 | 1.4% | Dec 8, 2020 | A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1. A remote atta... |
| CVE-2020-27821 | MEDIUM | 6 | 0.4% | Dec 8, 2020 | A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue cou... |
| CVE-2020-27758 | LOW | 3.3 | 1.1% | Dec 8, 2020 | A flaw was found in ImageMagick in coders/txt.c. An attacker who submits a crafted file that is processed by ImageMagick... |
| CVE-2020-27757 | LOW | 3.3 | 1.1% | Dec 8, 2020 | A floating point math calculation in ScaleAnyToQuantum() of /MagickCore/quantum-private.h could lead to undefined behavi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now