2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9065 | MEDIUM | 5.5 | 0.2% | Mar 26, 2020 | Huawei smart phone Taurus-AL00B with versions earlier than 10.0.0.203(C00E201R7P2) have a use-after-free (UAF) vulnerabi... |
| CVE-2020-7944 | HIGH | 7.7 | 0.9% | Mar 26, 2020 | In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive ... |
| CVE-2020-1800 | HIGH | 7.8 | 0.5% | Mar 26, 2020 | HUAWEI smartphones P30 with versions earlier than 10.0.0.185(C00E85R1P11) have an improper access control vulnerability.... |
| CVE-2020-4276 | HIGH | 7.5 | 3.1% | Mar 26, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerabilit... |
| CVE-2020-7260 | HIGH | 7.8 | 0.4% | Mar 26, 2020 | DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows loc... |
| CVE-2020-6999 | MEDIUM | 6.5 | 1.0% | Mar 26, 2020 | In Moxa EDS-G516E Series firmware, Version 5.2 or lower, some of the parameters in the setting pages do not ensure text ... |
| CVE-2020-5340 | MEDIUM | 4.8 | 0.7% | Mar 26, 2020 | RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security... |
| CVE-2020-5339 | MEDIUM | 4.8 | 0.7% | Mar 26, 2020 | RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security... |
| CVE-2020-5129 | HIGH | 7.5 | 1.3% | Mar 26, 2020 | A vulnerability in the SonicWall SMA1000 HTTP Extraweb server allows an unauthenticated remote attacker to cause HTTP se... |
| CVE-2020-1764 | HIGH | 8.6 | 3.5% | Mar 26, 2020 | A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to... |
| CVE-2020-10969 | HIGH | 8.8 | 3.6% | Mar 26, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-10968 | HIGH | 8.8 | 3.6% | Mar 26, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-8923 | MEDIUM | 6.1 | 0.3% | Mar 26, 2020 | An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an atta... |
| CVE-2020-8910 | MEDIUM | 6.5 | 0.5% | Mar 26, 2020 | A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker ... |
| CVE-2020-10245 | CRITICAL | 9.8 | 2.5% | Mar 26, 2020 | CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow. |
| CVE-2020-10966 | MEDIUM | 6.5 | 1.9% | Mar 25, 2020 | In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header ... |
| CVE-2020-10965 | HIGH | 8.1 | 1.4% | Mar 25, 2020 | Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetad... |
| CVE-2020-6815 | CRITICAL | 9.8 | 1.3% | Mar 25, 2020 | Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed eviden... |
| CVE-2020-6814 | CRITICAL | 9.8 | 1.8% | Mar 25, 2020 | Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed eviden... |
| CVE-2020-6813 | MEDIUM | 5.3 | 1.2% | Mar 25, 2020 | When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block cou... |
| CVE-2020-6812 | MEDIUM | 5.3 | 1.6% | Mar 25, 2020 | The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's A... |
| CVE-2020-6811 | HIGH | 8.8 | 3.2% | Mar 25, 2020 | The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be c... |
| CVE-2020-6810 | MEDIUM | 4.3 | 1.0% | Mar 25, 2020 | After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification th... |
| CVE-2020-6809 | HIGH | 7.5 | 1.4% | Mar 25, 2020 | When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possi... |
| CVE-2020-6808 | MEDIUM | 6.5 | 1.0% | Mar 25, 2020 | When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML doc... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now