2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4173 | MEDIUM | 4.3 | 0.9% | Jul 9, 2020 | IBM Guardium Activity Insights 10.6 and 11.0 does not set the secure attribute on authorization tokens or session cookie... |
| CVE-2020-15299 | MEDIUM | 6.1 | 47.0% | Jul 9, 2020 | A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remot... |
| CVE-2020-15093 | HIGH | 8.6 | 1.4% | Jul 9, 2020 | The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signat... |
| CVE-2020-15092 | MEDIUM | 4.8 | 1.1% | Jul 9, 2020 | In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with mali... |
| CVE-2020-15001 | MEDIUM | 5.3 | 0.6% | Jul 9, 2020 | An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP applicatio... |
| CVE-2020-15000 | MEDIUM | 5.9 | 0.7% | Jul 9, 2020 | A PIN management problem was discovered on Yubico YubiKey 5 devices 5.2.0 to 5.2.6. OpenPGP has three passwords: Admin P... |
| CVE-2020-14171 | MEDIUM | 6.5 | 0.6% | Jul 9, 2020 | Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repo... |
| CVE-2020-14170 | MEDIUM | 4.3 | 0.8% | Jul 9, 2020 | Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the cont... |
| CVE-2020-13132 | MEDIUM | 4.6 | 0.6% | Jul 9, 2020 | An issue was discovered in Yubico libykpiv before 2.1.0. An attacker can trigger an incorrect free() in the ykpiv_util_g... |
| CVE-2020-13131 | MEDIUM | 4.3 | 0.5% | Jul 9, 2020 | An issue was discovered in Yubico libykpiv before 2.1.0. lib/util.c in this library (which is included in yubico-piv-too... |
| CVE-2020-15526 | MEDIUM | 5.9 | 0.5% | Jul 9, 2020 | In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks ca... |
| CVE-2020-10756 | MEDIUM | 6.5 | 0.5% | Jul 9, 2020 | An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occ... |
| CVE-2020-13994 | HIGH | 8.8 | 7.4% | Jul 9, 2020 | An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the ser... |
| CVE-2020-13993 | HIGH | 7.5 | 2.1% | Jul 9, 2020 | An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A blind time-based SQL injection issue allows remote un... |
| CVE-2020-13992 | MEDIUM | 6.1 | 1.2% | Jul 9, 2020 | An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A Stored XSS issue allows remote unauthenticated attack... |
| CVE-2020-12426 | HIGH | 8.8 | 1.6% | Jul 9, 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed ev... |
| CVE-2020-12425 | MEDIUM | 6.5 | 1.4% | Jul 9, 2020 | Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leadi... |
| CVE-2020-12423 | HIGH | 7.8 | 0.4% | Jul 9, 2020 | When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in... |
| CVE-2020-12422 | HIGH | 8.8 | 1.9% | Jul 9, 2020 | In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, r... |
| CVE-2020-12421 | MEDIUM | 6.5 | 1.8% | Jul 9, 2020 | When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were le... |
| CVE-2020-12420 | HIGH | 8.8 | 1.9% | Jul 9, 2020 | When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to me... |
| CVE-2020-12419 | HIGH | 8.8 | 2.3% | Jul 9, 2020 | When processing callbacks that occurred during window flushing in the parent process, the associated window may die; cau... |
| CVE-2020-12418 | MEDIUM | 6.5 | 3.0% | Jul 9, 2020 | Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicio... |
| CVE-2020-12417 | HIGH | 8.8 | 2.7% | Jul 9, 2020 | Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory... |
| CVE-2020-12416 | HIGH | 8.8 | 1.4% | Jul 9, 2020 | A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now