2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9332 | HIGH | 7.8 | 0.5% | Jun 17, 2020 | ftusbbus2.sys in FabulaTech USB for Remote Desktop through 2020-02-19 allows privilege escalation via crafted IoCtl code... |
| CVE-2020-13637 | HIGH | 7.5 | 0.6% | Jun 17, 2020 | An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms... |
| CVE-2020-14400 | HIGH | 7.5 | 2.8% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvnc... |
| CVE-2020-14399 | HIGH | 7.5 | 2.8% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvnc... |
| CVE-2020-14398 | HIGH | 7.5 | 2.8% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in li... |
| CVE-2020-14397 | HIGH | 7.5 | 3.4% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference. |
| CVE-2020-14396 | HIGH | 7.5 | 2.6% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference. |
| CVE-2020-14295 | HIGH | 7.2 | 86.3% | Jun 17, 2020 | A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead... |
| CVE-2020-12827 | HIGH | 7.2 | 2.7% | Jun 17, 2020 | MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML docu... |
| CVE-2020-13224 | HIGH | 8.8 | 2.2% | Jun 17, 2020 | TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.... |
| CVE-2020-11904 | HIGH | 7.3 | 3.2% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Wri... |
| CVE-2020-11902 | HIGH | 7.3 | 9.3% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read. |
| CVE-2020-11900 | HIGH | 8.2 | 12.8% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free. |
| CVE-2020-4054 | HIGH | 7.3 | 1.9% | Jun 16, 2020 | In Sanitize (RubyGem sanitize) greater than or equal to 3.0.0 and less than 5.2.1, there is a cross-site scripting vulne... |
| CVE-2020-14212 | HIGH | 8.8 | 1.7% | Jun 16, 2020 | FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavformat/aviobuf.c because dnn_backend_native.... |
| CVE-2020-9289 | HIGH | 7.5 | 2.2% | Jun 16, 2020 | Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, For... |
| CVE-2020-7513 | HIGH | 7.5 | 0.8% | Jun 16, 2020 | A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy T300 (Firmware version 1.5.2 and o... |
| CVE-2020-7511 | HIGH | 7.5 | 0.9% | Jun 16, 2020 | A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy T300 (Firmware version 1.5.2... |
| CVE-2020-7510 | HIGH | 7.5 | 1.4% | Jun 16, 2020 | A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allo... |
| CVE-2020-7509 | HIGH | 7.2 | 1.2% | Jun 16, 2020 | A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older)... |
| CVE-2020-7507 | HIGH | 7.5 | 1.3% | Jun 16, 2020 | A CWE-400: Uncontrolled Resource Consumption vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) whi... |
| CVE-2020-7506 | HIGH | 7.5 | 1.3% | Jun 16, 2020 | A CWE-200: Information Exposure vulnerability exists in Easergy T300, Firmware V1.5.2 and prior, which could allow an at... |
| CVE-2020-7505 | HIGH | 7.2 | 0.9% | Jun 16, 2020 | A CWE-494 Download of Code Without Integrity Check vulnerability exists in Easergy T300 (Firmware version 1.5.2 and olde... |
| CVE-2020-7503 | HIGH | 8.8 | 0.6% | Jun 16, 2020 | A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) whi... |
| CVE-2020-7502 | HIGH | 7.5 | 1.5% | Jun 16, 2020 | A CWE-787: Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (Firmware version 4.3 and prior), w... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now