2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-16276HIGH8.8An SQL injection vulnerability in the Assets component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authe...
CVE-2020-16275MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.2...
CVE-2020-15139MEDIUM6.1In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rende...
CVE-2020-9245MEDIUM5.5HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions earlier than 10.1.0....
CVE-2020-9243MEDIUM5.5HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a denial of service vulnerability. The system doe...
CVE-2020-9078HIGH7.8FusionCompute 8.0.0 have local privilege escalation vulnerability. A local, authenticated attacker could perform specifi...
CVE-2020-17480MEDIUM6.1TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by...
CVE-2020-17479CRITICAL9.8jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.
CVE-2020-17478HIGH7.5ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplicati...
CVE-2020-15662MEDIUM6.5A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the ...
CVE-2020-15661MEDIUM6.5A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaki...
CVE-2020-15659HIGH8.8Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of...
CVE-2020-15658MEDIUM6.5The code for downloading files did not properly take care of special characters, which led to an attacker being able to ...
CVE-2020-15657HIGH7.8Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker tha...
CVE-2020-15656HIGH8.8JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mit...
CVE-2020-15655MEDIUM6.5A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leadi...
CVE-2020-15654MEDIUM6.5When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting ...
CVE-2020-15653MEDIUM6.5An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to...
CVE-2020-15652MEDIUM6.5By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin ...
CVE-2020-15651MEDIUM4.3A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI f...
CVE-2020-15650MEDIUM5.5Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite F...
CVE-2020-15649MEDIUM5.5Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choo...
CVE-2020-15648MEDIUM6.5Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-O...
CVE-2020-15647HIGH7.4A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, ...
CVE-2020-17476MEDIUM6.1Mibew Messenger before 3.2.7 allows XSS via a crafted user name.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now