2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12415MEDIUM6.5When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to...
CVE-2020-12414MEDIUM6.5IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was bei...
CVE-2020-12412MEDIUM4.3By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with...
CVE-2020-12411HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corru...
CVE-2020-12410HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evi...
CVE-2020-12409HIGH8.8When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This ...
CVE-2020-12408MEDIUM6.5When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path in...
CVE-2020-12407MEDIUM6.5Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary G...
CVE-2020-12406HIGH8.8Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We ...
CVE-2020-12405MEDIUM5.3When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploi...
CVE-2020-12404MEDIUM4.3For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging...
CVE-2020-12402MEDIUM4.4During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which enta...
CVE-2020-12399MEDIUM4.4NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private...
CVE-2020-12398HIGH7.5If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbi...
CVE-2020-7693MEDIUM5.3Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This ...
CVE-2020-7692CRITICAL9.1PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the a...
CVE-2020-7458CRITICAL9.8In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-c...
CVE-2020-7457HIGH8.1In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 1...
CVE-2020-5366MEDIUM6.5Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious us...
CVE-2020-12424MEDIUM6.5When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, a...
CVE-2020-11992Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-9377HIGH8.8D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability onl...
CVE-2020-9376HIGH7.5D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE...
CVE-2020-5604HIGH8.1Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a re...
CVE-2020-5974HIGH7.8NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are i...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now