2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13923 | MEDIUM | 5.3 | 5.0% | Jul 15, 2020 | IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04 |
| CVE-2020-7292 | MEDIUM | 4.3 | 0.9% | Jul 15, 2020 | Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attac... |
| CVE-2020-5765 | MEDIUM | 5.4 | 1.1% | Jul 15, 2020 | Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during sc... |
| CVE-2020-4100 | MEDIUM | 4.4 | 0.3% | Jul 15, 2020 | "HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which comp... |
| CVE-2020-1468 | MEDIUM | 6.5 | 5.2% | Jul 14, 2020 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m... |
| CVE-2020-1462 | MEDIUM | 4.3 | 4.2% | Jul 14, 2020 | An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), ... |
| CVE-2020-1456 | MEDIUM | 5.4 | 2.2% | Jul 14, 2020 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2020-1454 | MEDIUM | 5.4 | 1.6% | Jul 14, 2020 | This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affecte... |
| CVE-2020-1451 | MEDIUM | 5.4 | 1.6% | Jul 14, 2020 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2020-1450 | MEDIUM | 5.4 | 1.6% | Jul 14, 2020 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2020-1445 | MEDIUM | 5.5 | 6.1% | Jul 14, 2020 | An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, ak... |
| CVE-2020-1444 | MEDIUM | 4.3 | 9.1% | Jul 14, 2020 | A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email mes... |
| CVE-2020-1443 | MEDIUM | 5.4 | 1.7% | Jul 14, 2020 | A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requ... |
| CVE-2020-1442 | MEDIUM | 6.1 | 1.7% | Jul 14, 2020 | A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, a... |
| CVE-2020-1434 | MEDIUM | 5.3 | 0.8% | Jul 14, 2020 | An elevation of privilege vulnerability exists in the way that the Windows Sync Host Service handles objects in memory, ... |
| CVE-2020-1433 | MEDIUM | 6.5 | 5.3% | Jul 14, 2020 | An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka ... |
| CVE-2020-1432 | MEDIUM | 4.3 | 4.5% | Jul 14, 2020 | An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for... |
| CVE-2020-1426 | MEDIUM | 5.5 | 1.2% | Jul 14, 2020 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window... |
| CVE-2020-1420 | MEDIUM | 5.5 | 1.2% | Jul 14, 2020 | An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploi... |
| CVE-2020-1419 | MEDIUM | 5.5 | 1.3% | Jul 14, 2020 | An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, ak... |
| CVE-2020-1398 | MEDIUM | 6.8 | 1.2% | Jul 14, 2020 | An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An... |
| CVE-2020-1397 | MEDIUM | 6.5 | 6.4% | Jul 14, 2020 | An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle ob... |
| CVE-2020-1391 | MEDIUM | 5.5 | 1.2% | Jul 14, 2020 | An information disclosure vulnerability exists when the Windows Agent Activation Runtime (AarSvc) fails to properly hand... |
| CVE-2020-1389 | MEDIUM | 5.5 | 1.2% | Jul 14, 2020 | An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, ak... |
| CVE-2020-1386 | MEDIUM | 5.5 | 1.2% | Jul 14, 2020 | An information vulnerability exists when Windows Connected User Experiences and Telemetry Service improperly discloses f... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now