2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9065MEDIUM5.5Huawei smart phone Taurus-AL00B with versions earlier than 10.0.0.203(C00E201R7P2) have a use-after-free (UAF) vulnerabi...
CVE-2020-7944HIGH7.7In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive ...
CVE-2020-1800HIGH7.8HUAWEI smartphones P30 with versions earlier than 10.0.0.185(C00E85R1P11) have an improper access control vulnerability....
CVE-2020-4276HIGH7.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerabilit...
CVE-2020-7260HIGH7.8DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows loc...
CVE-2020-6999MEDIUM6.5In Moxa EDS-G516E Series firmware, Version 5.2 or lower, some of the parameters in the setting pages do not ensure text ...
CVE-2020-5340MEDIUM4.8RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security...
CVE-2020-5339MEDIUM4.8RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security...
CVE-2020-5129HIGH7.5A vulnerability in the SonicWall SMA1000 HTTP Extraweb server allows an unauthenticated remote attacker to cause HTTP se...
CVE-2020-1764HIGH8.6A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to...
CVE-2020-10969HIGH8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-10968HIGH8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-8923MEDIUM6.1An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an atta...
CVE-2020-8910MEDIUM6.5A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker ...
CVE-2020-10245CRITICAL9.8CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
CVE-2020-10966MEDIUM6.5In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header ...
CVE-2020-10965HIGH8.1Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetad...
CVE-2020-6815CRITICAL9.8Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed eviden...
CVE-2020-6814CRITICAL9.8Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed eviden...
CVE-2020-6813MEDIUM5.3When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block cou...
CVE-2020-6812MEDIUM5.3The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's A...
CVE-2020-6811HIGH8.8The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be c...
CVE-2020-6810MEDIUM4.3After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification th...
CVE-2020-6809HIGH7.5When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possi...
CVE-2020-6808MEDIUM6.5When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML doc...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now