2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-5249MEDIUM6.5In Puma (RubyGem) before 4.3.3 and 3.12.4, if an application using Puma allows untrusted input in an early-hints header,...
CVE-2020-4292MEDIUM5.3IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 uses a cross-domain policy file that include...
CVE-2020-4283HIGH8.6IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 contains hard-coded credentials, such as a p...
CVE-2020-5539MEDIUM6.5GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote at...
CVE-2020-9549HIGH7.8In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF document.
CVE-2020-6801HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 72. Some of these bugs showed evidence of memory corru...
CVE-2020-6800HIGH8.8Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of...
CVE-2020-6799HIGH8.8Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported fil...
CVE-2020-6798MEDIUM6.1If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when...
CVE-2020-6797MEDIUM4.3By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on ...
CVE-2020-6796HIGH8.8A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an ...
CVE-2020-6795MEDIUM6.5When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null poin...
CVE-2020-6794MEDIUM6.5If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passw...
CVE-2020-6793MEDIUM6.5When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location....
CVE-2020-6792MEDIUM4.3When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. Thi...
CVE-2020-9548CRITICAL9.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-9547CRITICAL9.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-9546CRITICAL9.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-9545HIGH7.5Pale Moon 28.x before 28.8.4 has a segmentation fault related to module scripting, as demonstrated by a Lacoste web site...
CVE-2020-9540HIGH7.8Sophos HitmanPro.Alert before build 861 allows local elevation of privilege.
CVE-2020-9535HIGH8.8fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup_Wizard webpage parameter ...
CVE-2020-9534HIGH8.8fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup webpage parameter when f_...
CVE-2020-6804MEDIUM6.1A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could ste...
CVE-2020-6803MEDIUM6.1An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site a...
CVE-2020-9459MEDIUM5.4Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1....

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now