2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4173MEDIUM4.3IBM Guardium Activity Insights 10.6 and 11.0 does not set the secure attribute on authorization tokens or session cookie...
CVE-2020-15299MEDIUM6.1A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remot...
CVE-2020-15093HIGH8.6The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signat...
CVE-2020-15092MEDIUM4.8In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with mali...
CVE-2020-15001MEDIUM5.3An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP applicatio...
CVE-2020-15000MEDIUM5.9A PIN management problem was discovered on Yubico YubiKey 5 devices 5.2.0 to 5.2.6. OpenPGP has three passwords: Admin P...
CVE-2020-14171MEDIUM6.5Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repo...
CVE-2020-14170MEDIUM4.3Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the cont...
CVE-2020-13132MEDIUM4.6An issue was discovered in Yubico libykpiv before 2.1.0. An attacker can trigger an incorrect free() in the ykpiv_util_g...
CVE-2020-13131MEDIUM4.3An issue was discovered in Yubico libykpiv before 2.1.0. lib/util.c in this library (which is included in yubico-piv-too...
CVE-2020-15526MEDIUM5.9In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks ca...
CVE-2020-10756MEDIUM6.5An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occ...
CVE-2020-13994HIGH8.8An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the ser...
CVE-2020-13993HIGH7.5An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A blind time-based SQL injection issue allows remote un...
CVE-2020-13992MEDIUM6.1An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A Stored XSS issue allows remote unauthenticated attack...
CVE-2020-12426HIGH8.8Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed ev...
CVE-2020-12425MEDIUM6.5Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leadi...
CVE-2020-12423HIGH7.8When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in...
CVE-2020-12422HIGH8.8In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, r...
CVE-2020-12421MEDIUM6.5When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were le...
CVE-2020-12420HIGH8.8When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to me...
CVE-2020-12419HIGH8.8When processing callbacks that occurred during window flushing in the parent process, the associated window may die; cau...
CVE-2020-12418MEDIUM6.5Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicio...
CVE-2020-12417HIGH8.8Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory...
CVE-2020-12416HIGH8.8A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now