2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-13112CRITICAL9.1An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to inf...
CVE-2020-6471CRITICAL9.6Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convin...
CVE-2020-6469CRITICAL9.6Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convin...
CVE-2020-6466CRITICAL9.6Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the rendere...
CVE-2020-6465CRITICAL9.6Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compro...
CVE-2020-6462CRITICAL9.6Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised ...
CVE-2020-6461CRITICAL9.6Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the rend...
CVE-2020-6457CRITICAL9.6Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially per...
CVE-2020-1955CRITICAL9.8CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server...
CVE-2020-11716CRITICAL9.8Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the...
CVE-2020-9409CRITICAL9.8The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS ...
CVE-2020-12835CRITICAL9.8An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an un...
CVE-2020-13226CRITICAL9.8WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibil...
CVE-2020-9753CRITICAL9.1Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.
CVE-2020-13167CRITICAL9.8Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain...
CVE-2020-13166CRITICAL9.8The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod...
CVE-2020-11715CRITICAL9.8Panasonic P99 devices through 2020-04-10 have Incorrect Access Control. NOTE: the vendor states that all affected produc...
CVE-2020-8434CRITICAL9.8Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch ...
CVE-2020-1897CRITICAL9.8A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invok...
CVE-2020-12258CRITICAL9.1rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application...
CVE-2020-12856CRITICAL9.8OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Andro...
CVE-2020-13126CRITICAL9.9An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in ...
CVE-2020-13118CRITICAL9.8An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community...
CVE-2020-13109CRITICAL9.8Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted...
CVE-2020-8149CRITICAL9.8Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before ve...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now