2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9800 | HIGH | 8.8 | 1.6% | Jun 9, 2020 | A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvO... |
| CVE-2020-9795 | HIGH | 7.8 | 1.3% | Jun 9, 2020 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.5 and iPadOS 13.5, m... |
| CVE-2020-9794 | HIGH | 8.1 | 1.6% | Jun 9, 2020 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macO... |
| CVE-2020-9793 | HIGH | 7.8 | 2.4% | Jun 9, 2020 | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5,... |
| CVE-2020-9791 | HIGH | 7.8 | 1.4% | Jun 9, 2020 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, mac... |
| CVE-2020-9790 | HIGH | 8.8 | 2.5% | Jun 9, 2020 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.... |
| CVE-2020-9789 | HIGH | 8.8 | 2.5% | Jun 9, 2020 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.... |
| CVE-2020-9788 | HIGH | 7.8 | 0.9% | Jun 9, 2020 | A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.5. A file... |
| CVE-2020-13978 | HIGH | 7.2 | 1.3% | Jun 9, 2020 | Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk... |
| CVE-2020-13976 | HIGH | 8.8 | 1.8% | Jun 9, 2020 | An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary comman... |
| CVE-2020-10757 | HIGH | 7.8 | 1.0% | Jun 9, 2020 | A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allow... |
| CVE-2020-5589 | HIGH | 8.8 | 0.6% | Jun 9, 2020 | SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X... |
| CVE-2020-13974 | HIGH | 7.8 | 0.6% | Jun 9, 2020 | An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_as... |
| CVE-2020-13962 | HIGH | 7.5 | 3.0% | Jun 9, 2020 | Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error qu... |
| CVE-2020-4038 | HIGH | 7.4 | 7.2% | Jun 8, 2020 | GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulne... |
| CVE-2020-13960 | HIGH | 7.5 | 1.2% | Jun 8, 2020 | D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search p... |
| CVE-2020-13885 | HIGH | 7.8 | 0.6% | Jun 8, 2020 | Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during ... |
| CVE-2020-13884 | HIGH | 7.8 | 0.6% | Jun 8, 2020 | Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows loc... |
| CVE-2020-13428 | HIGH | 7.8 | 2.4% | Jun 8, 2020 | A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media p... |
| CVE-2020-13432 | HIGH | 7.5 | 32.8% | Jun 8, 2020 | rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to ... |
| CVE-2020-5304 | HIGH | 7.5 | 1.0% | Jun 8, 2020 | The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a... |
| CVE-2020-13625 | HIGH | 7.5 | 3.8% | Jun 8, 2020 | PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote charac... |
| CVE-2020-12695 | HIGH | 7.5 | 15.2% | Jun 8, 2020 | The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription r... |
| CVE-2020-9042 | HIGH | 8.8 | 0.6% | Jun 8, 2020 | In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has us... |
| CVE-2020-9041 | HIGH | 7.5 | 1.3% | Jun 8, 2020 | In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now