2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3998MEDIUM6.5VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious att...
CVE-2020-3997MEDIUM5.4VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful ex...
CVE-2020-27216HIGH7In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta...
CVE-2020-26561HIGH8.8Belkin LINKSYS WRT160NL 1.0.04.002_US_20130619 devices have a stack-based buffer overflow vulnerability because of sprin...
CVE-2020-9361MEDIUM5.5CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause...
CVE-2020-9331HIGH7.8CryptoPro CSP through 5.0.0.10004 on 32-bit platforms allows Local Privilege Escalation (by local users with the SeChang...
CVE-2020-26887HIGH7.8FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.
CVE-2020-15004MEDIUM4.8OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS.
CVE-2020-15003MEDIUM4.3OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string o...
CVE-2020-15002MEDIUM5OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
CVE-2020-15270MEDIUM4.3Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid....
CVE-2020-3996MEDIUM5.5Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in infor...
CVE-2020-27675MEDIUM4.7An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_ba...
CVE-2020-27674MEDIUM5.3An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying ke...
CVE-2020-27673MEDIUM5.5An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a d...
CVE-2020-27672HIGH7An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve ...
CVE-2020-27671HIGH7.8An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data...
CVE-2020-27670HIGH7.8An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption)...
CVE-2020-25186HIGH7.5An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, wh...
CVE-2020-18129HIGH8.8A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.
CVE-2020-15684CRITICAL9.8Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corru...
CVE-2020-15683CRITICAL9.8Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of...
CVE-2020-15682MEDIUM6.5When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application...
CVE-2020-15681HIGH7.5When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could ha...
CVE-2020-15680MEDIUM5.3If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguis...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now