2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35206 | MEDIUM | 6.1 | 1.3% | Jan 11, 2021 | Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious... |
| CVE-2020-35204 | MEDIUM | 6.1 | 1.3% | Jan 11, 2021 | Reflected XSS in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via... |
| CVE-2020-35203 | MEDIUM | 6.1 | 1.3% | Jan 11, 2021 | Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious... |
| CVE-2020-5147 | MEDIUM | 5.3 | 1.7% | Jan 9, 2021 | SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to ... |
| CVE-2020-4733 | MEDIUM | 5.4 | 0.6% | Jan 8, 2021 | IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2020-4697 | MEDIUM | 5.4 | 0.6% | Jan 8, 2021 | IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2020-4691 | MEDIUM | 5.4 | 0.6% | Jan 8, 2021 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2020-4544 | MEDIUM | 4.3 | 1.0% | Jan 8, 2021 | IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical err... |
| CVE-2020-4487 | MEDIUM | 4.3 | 1.0% | Jan 8, 2021 | IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical err... |
| CVE-2020-5022 | MEDIUM | 5.3 | 1.0% | Jan 8, 2021 | IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which ca... |
| CVE-2020-5021 | MEDIUM | 4.4 | 0.2% | Jan 8, 2021 | IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a l... |
| CVE-2020-5020 | MEDIUM | 6.1 | 0.9% | Jan 8, 2021 | IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking action of the victi... |
| CVE-2020-5019 | MEDIUM | 6.5 | 1.3% | Jan 8, 2021 | IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of... |
| CVE-2020-5017 | MEDIUM | 5.5 | 0.3% | Jan 8, 2021 | IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow a local user to obtain access to information beyond their inte... |
| CVE-2020-26186 | MEDIUM | 6.8 | 0.4% | Jan 8, 2021 | Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local att... |
| CVE-2020-16042 | MEDIUM | 6.5 | 0.9% | Jan 8, 2021 | Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive... |
| CVE-2020-16040 | MEDIUM | 6.5 | 99.6% | Jan 8, 2021 | Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo... |
| CVE-2020-16036 | MEDIUM | 6.5 | 0.8% | Jan 8, 2021 | Inappropriate implementation in cookies in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass cooki... |
| CVE-2020-16034 | MEDIUM | 4.3 | 0.5% | Jan 8, 2021 | Inappropriate implementation in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a local attacker to bypass policy ... |
| CVE-2020-16033 | MEDIUM | 4.3 | 0.7% | Jan 8, 2021 | Inappropriate implementation in WebUSB in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof securit... |
| CVE-2020-16032 | MEDIUM | 4.3 | 0.7% | Jan 8, 2021 | Insufficient data validation in sharing in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the co... |
| CVE-2020-16031 | MEDIUM | 4.3 | 0.7% | Jan 8, 2021 | Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the content... |
| CVE-2020-16030 | MEDIUM | 6.1 | 0.7% | Jan 8, 2021 | Insufficient data validation in Blink in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to inject arbitra... |
| CVE-2020-16027 | MEDIUM | 6.5 | 0.8% | Jan 8, 2021 | Insufficient policy enforcement in developer tools in Google Chrome prior to 87.0.4280.66 allowed an attacker who convin... |
| CVE-2020-16012 | MEDIUM | 4.3 | 2.5% | Jan 8, 2021 | Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cr... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now