2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6541HIGH8.8Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap c...
CVE-2020-6540HIGH8.8Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap co...
CVE-2020-6539HIGH8.8Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corr...
CVE-2020-6538MEDIUM6.5Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to ...
CVE-2020-6537HIGH8.8Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside ...
CVE-2020-6532HIGH8.8Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap cor...
CVE-2020-15966MEDIUM4.3Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced ...
CVE-2020-15965HIGH8.8Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bou...
CVE-2020-15964HIGH8.8Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially e...
CVE-2020-15963CRITICAL9.6Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced ...
CVE-2020-15962HIGH8.8Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentiall...
CVE-2020-15961CRITICAL9.6Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a...
CVE-2020-15960HIGH8.8Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform...
CVE-2020-15959MEDIUM4.3Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced ...
CVE-2020-4643HIGH7.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack w...
CVE-2020-4731MEDIUM6.1IBM Aspera Web Application 1.9.14 PL1 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar...
CVE-2020-4590MEDIUM6.5IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server f...
CVE-2020-4581HIGH7.5IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sendi...
CVE-2020-4580HIGH7.5IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sendi...
CVE-2020-4579HIGH7.5IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sendi...
CVE-2020-4315MEDIUM4.3IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or sessi...
CVE-2020-16171MEDIUM6.5An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/...
CVE-2020-14180MEDIUM4.3Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-ad...
CVE-2020-14179MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field ...
CVE-2020-14177MEDIUM6.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availabili...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now