2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-16041 | HIGH | 8.1 | 2.1% | Jan 8, 2021 | Out of bounds read in networking in Google Chrome prior to 87.0.4280.88 allowed a remote attacker who had compromised th... |
| CVE-2020-16039 | HIGH | 8.8 | 1.2% | Jan 8, 2021 | Use after free in extensions in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit hea... |
| CVE-2020-16038 | HIGH | 8.8 | 1.2% | Jan 8, 2021 | Use after free in media in Google Chrome on OS X prior to 87.0.4280.88 allowed a remote attacker to potentially exploit ... |
| CVE-2020-16037 | HIGH | 8.8 | 1.2% | Jan 8, 2021 | Use after free in clipboard in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap... |
| CVE-2020-16035 | HIGH | 8.8 | 1.0% | Jan 8, 2021 | Insufficient data validation in cros-disks in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker ... |
| CVE-2020-16029 | HIGH | 8.8 | 0.9% | Jan 8, 2021 | Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass naviga... |
| CVE-2020-16028 | HIGH | 8.8 | 0.9% | Jan 8, 2021 | Heap buffer overflow in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit h... |
| CVE-2020-16026 | HIGH | 8.8 | 1.0% | Jan 8, 2021 | Use after free in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap co... |
| CVE-2020-16023 | HIGH | 8.8 | 0.9% | Jan 8, 2021 | Use after free in WebCodecs in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap... |
| CVE-2020-16022 | HIGH | 8.8 | 0.8% | Jan 8, 2021 | Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potent... |
| CVE-2020-16021 | HIGH | 7.5 | 0.6% | Jan 8, 2021 | Race in image burner in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised th... |
| CVE-2020-16020 | HIGH | 8.8 | 0.9% | Jan 8, 2021 | Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker ... |
| CVE-2020-16019 | HIGH | 8.8 | 0.9% | Jan 8, 2021 | Inappropriate implementation in filesystem in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker ... |
| CVE-2020-16015 | HIGH | 8.8 | 1.0% | Jan 8, 2021 | Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exp... |
| CVE-2020-16013 | HIGH | 8.8 | 2.8% | Jan 8, 2021 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially expl... |
| CVE-2020-26664 | HIGH | 7.8 | 1.5% | Jan 8, 2021 | A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based... |
| CVE-2020-17504 | HIGH | 7.2 | 2.8% | Jan 8, 2021 | The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that w... |
| CVE-2020-17503 | HIGH | 7.2 | 2.8% | Jan 8, 2021 | The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that w... |
| CVE-2020-17502 | HIGH | 7.2 | 2.8% | Jan 8, 2021 | Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which i... |
| CVE-2020-5805 | HIGH | 8.8 | 0.9% | Jan 8, 2021 | In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on ... |
| CVE-2020-5804 | HIGH | 8.1 | 1.7% | Jan 8, 2021 | Marvell QConvergeConsole GUI <= 5.5.0.74 is affected by a path traversal vulnerability. The deleteEventLogFile method of... |
| CVE-2020-24577 | HIGH | 7.5 | 19.1% | Jan 8, 2021 | An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch applicatio... |
| CVE-2020-36049 | HIGH | 7.5 | 2.6% | Jan 8, 2021 | socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet beca... |
| CVE-2020-36048 | HIGH | 7.5 | 3.3% | Jan 8, 2021 | Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the lo... |
| CVE-2020-13449 | HIGH | 7.5 | 4.9% | Jan 7, 2021 | A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any con... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now