2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-2279CRITICAL9.9A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to de...
CVE-2020-24626CRITICAL9.8Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execut...
CVE-2020-11856CRITICAL9.8Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. Th...
CVE-2020-11857CRITICAL9.8An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The...
CVE-2020-6573CRITICAL9.6Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised...
CVE-2020-15963CRITICAL9.6Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced ...
CVE-2020-15961CRITICAL9.6Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a...
CVE-2020-25787CRITICAL9.8An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting...
CVE-2020-8158CRITICAL9.8Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties...
CVE-2020-15181CRITICAL9.8The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can...
CVE-2020-15188CRITICAL9.8SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to...
CVE-2020-0354CRITICAL9.8In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code exec...
CVE-2020-25756CRITICAL9.8A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of boun...
CVE-2020-0333CRITICAL9.8In UrlQuerySanitizer, there is a possible improper input validation. This could lead to remote code execution with no ad...
CVE-2020-15182CRITICAL9.6The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). T...
CVE-2020-25216CRITICAL9.8yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction w...
CVE-2020-25215CRITICAL9.8yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document.
CVE-2020-25489CRITICAL9.8A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploi...
CVE-2020-24753CRITICAL9.8A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow a...
CVE-2020-13169CRITICAL9Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and p...
CVE-2020-11698CRITICAL9.8An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp...
CVE-2020-0380CRITICAL9.8In allocExcessBits of bitalloc.c, there is a possible out of bounds write due to an incorrect bounds check. This could l...
CVE-2020-0342CRITICAL9.8There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID...
CVE-2020-0278CRITICAL9.8There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID...
CVE-2020-0229CRITICAL9.8There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now