2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12389CRITICAL10The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note...
CVE-2020-12388CRITICAL10The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note...
CVE-2020-12387HIGH8.1A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a pot...
CVE-2020-12396CRITICAL9.8Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed ev...
CVE-2020-12395CRITICAL9.8Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of...
CVE-2020-12394LOW3.3A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by sel...
CVE-2020-12393HIGH7.8The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be c...
CVE-2020-8171CRITICAL9.8We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie...
CVE-2020-8170MEDIUM6.1We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie...
CVE-2020-8168HIGH8.8We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie...
CVE-2020-11970Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-10719MEDIUM6.5A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with larg...
CVE-2020-10751MEDIUM6.1A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed t...
CVE-2020-13487MEDIUM4.8The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript exe...
CVE-2020-3812MEDIUM5.5qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for...
CVE-2020-3811HIGH7.5qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
CVE-2020-13486MEDIUM6.1The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.
CVE-2020-13485CRITICAL9.1The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
CVE-2020-13482HIGH7.4EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-m...
CVE-2020-13459MEDIUM5.4An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize a...
CVE-2020-13458HIGH8.8An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear...
CVE-2020-13442CRITICAL9.8A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP f...
CVE-2020-5537CRITICAL9.8Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors.
CVE-2020-13440MEDIUM6.5ffjpeg through 2020-02-24 has an invalid write in bmp_load in bmp.c.
CVE-2020-13439MEDIUM6.5ffjpeg through 2020-02-24 has a heap-based buffer over-read in jfif_decode in jfif.c.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now