2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10068 | MEDIUM | 6.5 | 0.5% | Jun 5, 2020 | In the Zephyr project Bluetooth subsystem, certain duplicate and back-to-back packets can cause incorrect behavior, resu... |
| CVE-2020-8555 | MEDIUM | 6.3 | 3.7% | Jun 5, 2020 | The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version ... |
| CVE-2020-9074 | MEDIUM | 5.3 | 0.7% | Jun 5, 2020 | Huawei Smartphones HONOR 20 PRO;Honor View 20;HONOR 20 have an improper handling of exceptional condition Vulnerability.... |
| CVE-2020-1883 | MEDIUM | 4.9 | 0.8% | Jun 5, 2020 | Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with high privileges exp... |
| CVE-2020-12849 | MEDIUM | 5.4 | 0.8% | Jun 5, 2020 | Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user r... |
| CVE-2020-12848 | MEDIUM | 5.4 | 1.1% | Jun 5, 2020 | In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden share... |
| CVE-2020-13843 | MEDIUM | 5.5 | 0.1% | Jun 5, 2020 | An issue was discovered on LG mobile devices with Android OS software before 2020-06-01. Local users can cause a denial ... |
| CVE-2020-12853 | MEDIUM | 6.1 | 0.8% | Jun 4, 2020 | Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially maliciou... |
| CVE-2020-12852 | MEDIUM | 6.8 | 2.4% | Jun 4, 2020 | The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key ... |
| CVE-2020-11682 | MEDIUM | 6.5 | 0.6% | Jun 4, 2020 | Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by th... |
| CVE-2020-11680 | MEDIUM | 6.5 | 1.2% | Jun 4, 2020 | Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fail... |
| CVE-2020-10702 | MEDIUM | 5.5 | 0.3% | Jun 4, 2020 | A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in versi... |
| CVE-2020-9462 | MEDIUM | 4.3 | 0.3% | Jun 4, 2020 | An issue was discovered in all Athom Homey and Homey Pro devices up to the current version 4.2.0. An attacker within RF ... |
| CVE-2020-13800 | MEDIUM | 6 | 0.5% | Jun 4, 2020 | ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index val... |
| CVE-2020-13791 | MEDIUM | 5.5 | 0.4% | Jun 4, 2020 | hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end... |
| CVE-2020-13765 | MEDIUM | 5.6 | 2.4% | Jun 4, 2020 | rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which all... |
| CVE-2020-13827 | MEDIUM | 6.1 | 0.8% | Jun 4, 2020 | phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php. |
| CVE-2020-4191 | MEDIUM | 4.4 | 0.2% | Jun 4, 2020 | IBM Security Guardium 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hi... |
| CVE-2020-4183 | MEDIUM | 6.1 | 0.7% | Jun 4, 2020 | IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2020-6640 | MEDIUM | 5.4 | 0.9% | Jun 4, 2020 | An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated... |
| CVE-2020-7030 | MEDIUM | 5.5 | 1.0% | Jun 4, 2020 | A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may pot... |
| CVE-2020-6504 | MEDIUM | 4.3 | 0.5% | Jun 3, 2020 | Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to by... |
| CVE-2020-6503 | MEDIUM | 6.5 | 0.7% | Jun 3, 2020 | Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtai... |
| CVE-2020-6502 | MEDIUM | 6.5 | 0.7% | Jun 3, 2020 | Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof securi... |
| CVE-2020-6501 | MEDIUM | 6.5 | 0.7% | Jun 3, 2020 | Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass conten... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now