2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7456 | MEDIUM | 6.8 | 0.6% | Jun 9, 2020 | In FreeBSD 12.1-STABLE before r361918, 12.1-RELEASE before p6, 11.4-STABLE before r361919, 11.3-RELEASE before p10, and ... |
| CVE-2020-13911 | MEDIUM | 5.4 | 0.6% | Jun 9, 2020 | Your Online Shop 1.8.0 allows authenticated users to trigger XSS via a Change Name or Change Surname operation. |
| CVE-2020-13892 | MEDIUM | 5.4 | 0.7% | Jun 9, 2020 | The SportsPress plugin before 2.7.2 for WordPress allows XSS. |
| CVE-2020-9856 | MEDIUM | 5.3 | 1.4% | Jun 9, 2020 | This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able... |
| CVE-2020-9851 | MEDIUM | 5.5 | 0.6% | Jun 9, 2020 | An access issue was addressed with improved access restrictions. This issue is fixed in macOS Catalina 10.15.5. A malici... |
| CVE-2020-9835 | MEDIUM | 5.3 | 0.7% | Jun 9, 2020 | An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This issue is fixed in iO... |
| CVE-2020-9833 | MEDIUM | 5.5 | 0.3% | Jun 9, 2020 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.5... |
| CVE-2020-9832 | MEDIUM | 5.5 | 0.7% | Jun 9, 2020 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.5. A mal... |
| CVE-2020-9831 | MEDIUM | 5.5 | 0.7% | Jun 9, 2020 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A mali... |
| CVE-2020-9829 | MEDIUM | 6.5 | 1.0% | Jun 9, 2020 | A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS... |
| CVE-2020-9819 | MEDIUM | 4.3 | 2.2% | Jun 9, 2020 | A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5,... |
| CVE-2020-9812 | MEDIUM | 5.5 | 0.8% | Jun 9, 2020 | An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS... |
| CVE-2020-9811 | MEDIUM | 5.5 | 0.8% | Jun 9, 2020 | An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS... |
| CVE-2020-9809 | MEDIUM | 5.5 | 0.9% | Jun 9, 2020 | An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS... |
| CVE-2020-9804 | MEDIUM | 4.6 | 0.3% | Jun 9, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. Inserting a USB d... |
| CVE-2020-9801 | MEDIUM | 5.3 | 1.4% | Jun 9, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1.1. A malicious process may ca... |
| CVE-2020-9797 | MEDIUM | 5.5 | 0.8% | Jun 9, 2020 | An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.5 and iPadO... |
| CVE-2020-9792 | MEDIUM | 4.6 | 0.3% | Jun 9, 2020 | A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, macO... |
| CVE-2020-3882 | MEDIUM | 6.5 | 1.2% | Jun 9, 2020 | This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. Importing a maliciously cr... |
| CVE-2020-13266 | MEDIUM | 4.3 | 0.6% | Jun 9, 2020 | Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permi... |
| CVE-2020-13980 | MEDIUM | 4.8 | 0.7% | Jun 9, 2020 | OpenCart 3.0.3.3 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upl... |
| CVE-2020-13977 | MEDIUM | 4.9 | 2.9% | Jun 9, 2020 | Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration s... |
| CVE-2020-10761 | MEDIUM | 5 | 1.8% | Jun 9, 2020 | An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. Thi... |
| CVE-2020-13973 | MEDIUM | 6.1 | 1.1% | Jun 9, 2020 | OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls anoth... |
| CVE-2020-13965 | MEDIUM | 6.1 | 76.6% | Jun 9, 2020 | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML atta... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now