2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-16276 | HIGH | 8.8 | 1.2% | Aug 10, 2020 | An SQL injection vulnerability in the Assets component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authe... |
| CVE-2020-16275 | MEDIUM | 6.1 | 0.6% | Aug 10, 2020 | A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.2... |
| CVE-2020-15139 | MEDIUM | 6.1 | 1.3% | Aug 10, 2020 | In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rende... |
| CVE-2020-9245 | MEDIUM | 5.5 | 0.5% | Aug 10, 2020 | HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions earlier than 10.1.0.... |
| CVE-2020-9243 | MEDIUM | 5.5 | 0.5% | Aug 10, 2020 | HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a denial of service vulnerability. The system doe... |
| CVE-2020-9078 | HIGH | 7.8 | 0.2% | Aug 10, 2020 | FusionCompute 8.0.0 have local privilege escalation vulnerability. A local, authenticated attacker could perform specifi... |
| CVE-2020-17480 | MEDIUM | 6.1 | 1.2% | Aug 10, 2020 | TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by... |
| CVE-2020-17479 | CRITICAL | 9.8 | 2.5% | Aug 10, 2020 | jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array. |
| CVE-2020-17478 | HIGH | 7.5 | 1.1% | Aug 10, 2020 | ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplicati... |
| CVE-2020-15662 | MEDIUM | 6.5 | 0.7% | Aug 10, 2020 | A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the ... |
| CVE-2020-15661 | MEDIUM | 6.5 | 0.8% | Aug 10, 2020 | A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaki... |
| CVE-2020-15659 | HIGH | 8.8 | 2.4% | Aug 10, 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of... |
| CVE-2020-15658 | MEDIUM | 6.5 | 1.2% | Aug 10, 2020 | The code for downloading files did not properly take care of special characters, which led to an attacker being able to ... |
| CVE-2020-15657 | HIGH | 7.8 | 0.4% | Aug 10, 2020 | Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker tha... |
| CVE-2020-15656 | HIGH | 8.8 | 1.5% | Aug 10, 2020 | JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mit... |
| CVE-2020-15655 | MEDIUM | 6.5 | 1.5% | Aug 10, 2020 | A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leadi... |
| CVE-2020-15654 | MEDIUM | 6.5 | 1.2% | Aug 10, 2020 | When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting ... |
| CVE-2020-15653 | MEDIUM | 6.5 | 1.2% | Aug 10, 2020 | An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to... |
| CVE-2020-15652 | MEDIUM | 6.5 | 1.3% | Aug 10, 2020 | By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin ... |
| CVE-2020-15651 | MEDIUM | 4.3 | 0.6% | Aug 10, 2020 | A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI f... |
| CVE-2020-15650 | MEDIUM | 5.5 | 0.6% | Aug 10, 2020 | Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite F... |
| CVE-2020-15649 | MEDIUM | 5.5 | 0.7% | Aug 10, 2020 | Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choo... |
| CVE-2020-15648 | MEDIUM | 6.5 | 1.1% | Aug 10, 2020 | Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-O... |
| CVE-2020-15647 | HIGH | 7.4 | 1.1% | Aug 10, 2020 | A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, ... |
| CVE-2020-17476 | MEDIUM | 6.1 | 0.7% | Aug 10, 2020 | Mibew Messenger before 3.2.7 allows XSS via a crafted user name. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now