2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26519MEDIUM5.5Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a de...
CVE-2020-26518CRITICAL9.8Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/...
CVE-2020-26511HIGH7.5The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This lead...
CVE-2020-9491HIGH7.5In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connectio...
CVE-2020-9487HIGH7.5In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did no...
CVE-2020-9486HIGH7.5In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive proper...
CVE-2020-5789MEDIUM6.5Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the cont...
CVE-2020-5788MEDIUM6.5Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitr...
CVE-2020-5787MEDIUM6.5Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitr...
CVE-2020-5786HIGH8.8Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive applica...
CVE-2020-5785MEDIUM6.1Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct r...
CVE-2020-5784MEDIUM6.5Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the applicatio...
CVE-2020-5387MEDIUM4.4Dell XPS 13 9370 BIOS versions prior to 1.13.1 contains an Improper Exception Handling vulnerability. A local attacker w...
CVE-2020-14223MEDIUM6.1HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed i...
CVE-2020-13940MEDIUM5.5In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider o...
CVE-2020-11979HIGH7.5As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the...
CVE-2020-15678HIGH8.8When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential u...
CVE-2020-15677MEDIUM6.1By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the down...
CVE-2020-15676MEDIUM6.1Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScr...
CVE-2020-15675HIGH8.8When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially ex...
CVE-2020-15674HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corru...
CVE-2020-15673HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evi...
CVE-2020-15671LOW3.1When typing in a password under certain conditions, a race may have occured where the InputContext was not being correct...
CVE-2020-15670HIGH8.8Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of ...
CVE-2020-15669HIGH8.8When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. T...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now