2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14940 | HIGH | 7.5 | 3.6% | Jun 23, 2020 | An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading ... |
| CVE-2020-14939 | HIGH | 7.8 | 1.3% | Jun 23, 2020 | An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts th... |
| CVE-2020-4031 | HIGH | 7.5 | 1.8% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility ... |
| CVE-2020-14945 | HIGH | 8.8 | 11.4% | Jun 22, 2020 | A privilege escalation vulnerability exists within Global RADAR BSA Radar 1.6.7234.24750 and earlier that allows an auth... |
| CVE-2020-14990 | HIGH | 7.1 | 0.5% | Jun 22, 2020 | IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Cl... |
| CVE-2020-14049 | HIGH | 7.5 | 2.2% | Jun 22, 2020 | Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber... |
| CVE-2020-13158 | HIGH | 7.5 | 53.5% | Jun 22, 2020 | Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parame... |
| CVE-2020-11520 | HIGH | 7.8 | 0.4% | Jun 22, 2020 | The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to write to arbitrary kernel memory ad... |
| CVE-2020-11519 | HIGH | 7.8 | 0.8% | Jun 22, 2020 | The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to read or write to physical disc sect... |
| CVE-2020-10740 | HIGH | 7.5 | 1.7% | Jun 22, 2020 | A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible ... |
| CVE-2020-10736 | HIGH | 8 | 0.6% | Jun 22, 2020 | An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr d... |
| CVE-2020-6644 | HIGH | 8.1 | 1.0% | Jun 22, 2020 | An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpi... |
| CVE-2020-4066 | HIGH | 7.2 | 1.6% | Jun 22, 2020 | In Limdu before 0.95, the trainBatch function has a command injection vulnerability. Clients of the Limdu library are un... |
| CVE-2020-13887 | HIGH | 8.8 | 2.4% | Jun 22, 2020 | documents_add.php in Kordil EDMS through 2.2.60rc3 allows Remote Command Execution because .php files can be uploaded to... |
| CVE-2020-13279 | HIGH | 8.6 | 1.2% | Jun 22, 2020 | Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system |
| CVE-2020-8933 | HIGH | 7.8 | 0.4% | Jun 22, 2020 | A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on... |
| CVE-2020-8907 | HIGH | 7.8 | 0.3% | Jun 22, 2020 | A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on... |
| CVE-2020-8903 | HIGH | 7.8 | 0.3% | Jun 22, 2020 | A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on... |
| CVE-2020-14461 | HIGH | 8.6 | 9.5% | Jun 22, 2020 | Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI. |
| CVE-2020-14204 | HIGH | 8.2 | 1.9% | Jun 22, 2020 | In WebFOCUS Business Intelligence 8.0 (SP6), the administration portal allows remote attackers to read arbitrary local f... |
| CVE-2020-14203 | HIGH | 8.8 | 0.5% | Jun 22, 2020 | WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users ... |
| CVE-2020-14969 | HIGH | 7.5 | 1.3% | Jun 22, 2020 | app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the att... |
| CVE-2020-14966 | HIGH | 7.5 | 1.1% | Jun 22, 2020 | An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signature... |
| CVE-2020-8102 | HIGH | 8.8 | 1.1% | Jun 22, 2020 | Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an ex... |
| CVE-2020-3676 | HIGH | 7.8 | 0.2% | Jun 22, 2020 | Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdr... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now