2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6541 | HIGH | 8.8 | 22.9% | Sep 21, 2020 | Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap c... |
| CVE-2020-6540 | HIGH | 8.8 | 1.5% | Sep 21, 2020 | Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap co... |
| CVE-2020-6539 | HIGH | 8.8 | 1.0% | Sep 21, 2020 | Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2020-6538 | MEDIUM | 6.5 | 1.0% | Sep 21, 2020 | Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to ... |
| CVE-2020-6537 | HIGH | 8.8 | 1.6% | Sep 21, 2020 | Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside ... |
| CVE-2020-6532 | HIGH | 8.8 | 1.3% | Sep 21, 2020 | Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2020-15966 | MEDIUM | 4.3 | 1.3% | Sep 21, 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced ... |
| CVE-2020-15965 | HIGH | 8.8 | 3.4% | Sep 21, 2020 | Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bou... |
| CVE-2020-15964 | HIGH | 8.8 | 2.9% | Sep 21, 2020 | Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially e... |
| CVE-2020-15963 | CRITICAL | 9.6 | 1.5% | Sep 21, 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced ... |
| CVE-2020-15962 | HIGH | 8.8 | 1.9% | Sep 21, 2020 | Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentiall... |
| CVE-2020-15961 | CRITICAL | 9.6 | 1.5% | Sep 21, 2020 | Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a... |
| CVE-2020-15960 | HIGH | 8.8 | 1.9% | Sep 21, 2020 | Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform... |
| CVE-2020-15959 | MEDIUM | 4.3 | 1.2% | Sep 21, 2020 | Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced ... |
| CVE-2020-4643 | HIGH | 7.5 | 2.8% | Sep 21, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack w... |
| CVE-2020-4731 | MEDIUM | 6.1 | 0.7% | Sep 21, 2020 | IBM Aspera Web Application 1.9.14 PL1 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar... |
| CVE-2020-4590 | MEDIUM | 6.5 | 1.2% | Sep 21, 2020 | IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server f... |
| CVE-2020-4581 | HIGH | 7.5 | 1.6% | Sep 21, 2020 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sendi... |
| CVE-2020-4580 | HIGH | 7.5 | 1.6% | Sep 21, 2020 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sendi... |
| CVE-2020-4579 | HIGH | 7.5 | 2.2% | Sep 21, 2020 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sendi... |
| CVE-2020-4315 | MEDIUM | 4.3 | 1.2% | Sep 21, 2020 | IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or sessi... |
| CVE-2020-16171 | MEDIUM | 6.5 | 5.5% | Sep 21, 2020 | An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/... |
| CVE-2020-14180 | MEDIUM | 4.3 | 0.8% | Sep 21, 2020 | Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-ad... |
| CVE-2020-14179 | MEDIUM | 5.3 | 76.0% | Sep 21, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field ... |
| CVE-2020-14177 | MEDIUM | 6.5 | 2.2% | Sep 21, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availabili... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now