2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12389 | CRITICAL | 10 | 1.7% | May 26, 2020 | The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note... |
| CVE-2020-12388 | CRITICAL | 10 | 2.7% | May 26, 2020 | The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note... |
| CVE-2020-12387 | HIGH | 8.1 | 1.4% | May 26, 2020 | A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a pot... |
| CVE-2020-12396 | CRITICAL | 9.8 | 1.7% | May 26, 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed ev... |
| CVE-2020-12395 | CRITICAL | 9.8 | 2.3% | May 26, 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of... |
| CVE-2020-12394 | LOW | 3.3 | 0.3% | May 26, 2020 | A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by sel... |
| CVE-2020-12393 | HIGH | 7.8 | 1.0% | May 26, 2020 | The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be c... |
| CVE-2020-8171 | CRITICAL | 9.8 | 3.9% | May 26, 2020 | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie... |
| CVE-2020-8170 | MEDIUM | 6.1 | 1.0% | May 26, 2020 | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie... |
| CVE-2020-8168 | HIGH | 8.8 | 0.7% | May 26, 2020 | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie... |
| CVE-2020-11970 | — | — | — | May 26, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-10719 | MEDIUM | 6.5 | 1.0% | May 26, 2020 | A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with larg... |
| CVE-2020-10751 | MEDIUM | 6.1 | 0.3% | May 26, 2020 | A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed t... |
| CVE-2020-13487 | MEDIUM | 4.8 | 1.4% | May 26, 2020 | The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript exe... |
| CVE-2020-3812 | MEDIUM | 5.5 | 0.4% | May 26, 2020 | qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for... |
| CVE-2020-3811 | HIGH | 7.5 | 1.8% | May 26, 2020 | qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability. |
| CVE-2020-13486 | MEDIUM | 6.1 | 0.7% | May 25, 2020 | The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection. |
| CVE-2020-13485 | CRITICAL | 9.1 | 1.4% | May 25, 2020 | The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header. |
| CVE-2020-13482 | HIGH | 7.4 | 0.9% | May 25, 2020 | EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-m... |
| CVE-2020-13459 | MEDIUM | 5.4 | 0.5% | May 25, 2020 | An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize a... |
| CVE-2020-13458 | HIGH | 8.8 | 0.5% | May 25, 2020 | An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear... |
| CVE-2020-13442 | CRITICAL | 9.8 | 2.6% | May 25, 2020 | A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP f... |
| CVE-2020-5537 | CRITICAL | 9.8 | 2.9% | May 25, 2020 | Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors. |
| CVE-2020-13440 | MEDIUM | 6.5 | 0.8% | May 24, 2020 | ffjpeg through 2020-02-24 has an invalid write in bmp_load in bmp.c. |
| CVE-2020-13439 | MEDIUM | 6.5 | 0.8% | May 24, 2020 | ffjpeg through 2020-02-24 has a heap-based buffer over-read in jfif_decode in jfif.c. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now