2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12415 | MEDIUM | 6.5 | 1.3% | Jul 9, 2020 | When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to... |
| CVE-2020-12414 | MEDIUM | 6.5 | 0.7% | Jul 9, 2020 | IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was bei... |
| CVE-2020-12412 | MEDIUM | 4.3 | 0.8% | Jul 9, 2020 | By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with... |
| CVE-2020-12411 | HIGH | 8.8 | 1.2% | Jul 9, 2020 | Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corru... |
| CVE-2020-12410 | HIGH | 8.8 | 1.5% | Jul 9, 2020 | Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evi... |
| CVE-2020-12409 | HIGH | 8.8 | 1.0% | Jul 9, 2020 | When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This ... |
| CVE-2020-12408 | MEDIUM | 6.5 | 0.8% | Jul 9, 2020 | When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path in... |
| CVE-2020-12407 | MEDIUM | 6.5 | 1.0% | Jul 9, 2020 | Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary G... |
| CVE-2020-12406 | HIGH | 8.8 | 1.0% | Jul 9, 2020 | Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We ... |
| CVE-2020-12405 | MEDIUM | 5.3 | 1.4% | Jul 9, 2020 | When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploi... |
| CVE-2020-12404 | MEDIUM | 4.3 | 0.8% | Jul 9, 2020 | For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging... |
| CVE-2020-12402 | MEDIUM | 4.4 | 0.3% | Jul 9, 2020 | During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which enta... |
| CVE-2020-12399 | MEDIUM | 4.4 | 0.7% | Jul 9, 2020 | NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private... |
| CVE-2020-12398 | HIGH | 7.5 | 1.0% | Jul 9, 2020 | If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbi... |
| CVE-2020-7693 | MEDIUM | 5.3 | 5.0% | Jul 9, 2020 | Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This ... |
| CVE-2020-7692 | CRITICAL | 9.1 | 1.6% | Jul 9, 2020 | PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the a... |
| CVE-2020-7458 | CRITICAL | 9.8 | 1.9% | Jul 9, 2020 | In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-c... |
| CVE-2020-7457 | HIGH | 8.1 | 33.0% | Jul 9, 2020 | In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 1... |
| CVE-2020-5366 | MEDIUM | 6.5 | 1.8% | Jul 9, 2020 | Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious us... |
| CVE-2020-12424 | MEDIUM | 6.5 | 1.4% | Jul 9, 2020 | When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, a... |
| CVE-2020-11992 | — | — | — | Jul 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-9377 | HIGH | 8.8 | 21.3% | Jul 9, 2020 | D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability onl... |
| CVE-2020-9376 | HIGH | 7.5 | 16.6% | Jul 9, 2020 | D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE... |
| CVE-2020-5604 | HIGH | 8.1 | 2.0% | Jul 9, 2020 | Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a re... |
| CVE-2020-5974 | HIGH | 7.8 | 0.3% | Jul 8, 2020 | NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are i... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now