2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13818HIGH7.5In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.
CVE-2020-13817HIGH7.4ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit o...
CVE-2020-13777HIGH7.4GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS...
CVE-2020-10549CRITICAL9.8rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' pass...
CVE-2020-10548CRITICAL9.8rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passw...
CVE-2020-10547CRITICAL9.8rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by defa...
CVE-2020-10546CRITICAL9.8rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, n...
CVE-2020-7030MEDIUM5.5A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may pot...
CVE-2020-11094CRITICAL9.8The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all informat...
CVE-2020-6504MEDIUM4.3Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to by...
CVE-2020-6503MEDIUM6.5Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtai...
CVE-2020-6502MEDIUM6.5Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof securi...
CVE-2020-6501MEDIUM6.5Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass conten...
CVE-2020-6500MEDIUM6.5Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof ...
CVE-2020-6499MEDIUM6.5Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass AppC...
CVE-2020-6498MEDIUM6.5Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to pe...
CVE-2020-6497MEDIUM6.5Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to pe...
CVE-2020-6496HIGH8.8Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perf...
CVE-2020-6495MEDIUM6.5Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convin...
CVE-2020-6494MEDIUM6.5Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof t...
CVE-2020-6493CRITICAL9.6Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised...
CVE-2020-6453HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially expl...
CVE-2020-6419HIGH8.8Out of bounds write in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap c...
CVE-2020-11091MEDIUM5.8In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS re...
CVE-2020-11080HIGH7.5In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now