2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9040 | HIGH | 7.5 | 0.7% | Jun 8, 2020 | Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intende... |
| CVE-2020-13866 | HIGH | 7.8 | 1.1% | Jun 8, 2020 | WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges... |
| CVE-2020-8172 | HIGH | 7.4 | 6.1% | Jun 8, 2020 | TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0. |
| CVE-2020-6110 | HIGH | 8.8 | 4.3% | Jun 8, 2020 | An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages incl... |
| CVE-2020-4529 | HIGH | 7.4 | 0.8% | Jun 8, 2020 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authe... |
| CVE-2020-12773 | HIGH | 8.8 | 1.2% | Jun 8, 2020 | A security misconfiguration vulnerability exists in the SDK of some Realtek ADSL/PON Modem SoC firmware, which allows at... |
| CVE-2020-13912 | HIGH | 7.3 | 1.1% | Jun 7, 2020 | SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, b... |
| CVE-2020-13902 | HIGH | 7.1 | 1.0% | Jun 7, 2020 | ImageMagick 7.0.9-27 through 7.0.10-17 has a heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c duri... |
| CVE-2020-13895 | HIGH | 8.8 | 0.7% | Jun 7, 2020 | Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA sign... |
| CVE-2020-13894 | HIGH | 7.5 | 1.1% | Jun 7, 2020 | handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the sa... |
| CVE-2020-13881 | HIGH | 7.5 | 1.7% | Jun 6, 2020 | In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel ... |
| CVE-2020-13871 | HIGH | 7.5 | 4.4% | Jun 6, 2020 | SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions i... |
| CVE-2020-13646 | HIGH | 7.8 | 0.4% | Jun 5, 2020 | In Cheetah free WiFi 5.1, the driver file (liebaonat.sys) allows local users to cause a denial of service (BSOD) or poss... |
| CVE-2020-5591 | HIGH | 7.5 | 1.6% | Jun 5, 2020 | XACK DNS 1.11.0 to 1.11.4, 1.10.0 to 1.10.8, 1.8.0 to 1.8.23, 1.7.0 to 1.7.18, and versions before 1.7.0 allow remote at... |
| CVE-2020-10063 | HIGH | 7.5 | 1.8% | Jun 5, 2020 | A remote adversary with the ability to send arbitrary CoAP packets to be parsed by Zephyr is able to cause a denial of s... |
| CVE-2020-10061 | HIGH | 8.8 | 0.6% | Jun 5, 2020 | Improper handling of the full-buffer case in the Zephyr Bluetooth implementation can result in memory corruption. This i... |
| CVE-2020-8103 | HIGH | 7.1 | 0.8% | Jun 5, 2020 | A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user ... |
| CVE-2020-4449 | HIGH | 7.5 | 3.9% | Jun 5, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive in... |
| CVE-2020-4229 | HIGH | 7.3 | 0.9% | Jun 5, 2020 | IBM Worklight/MobileFoundation 8.0.0.0 does not properly invalidate session cookies when a user logs out of a session, w... |
| CVE-2020-9859 | HIGH | 7.8 | 0.8% | Jun 5, 2020 | A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.... |
| CVE-2020-12723 | HIGH | 7.5 | 6.0% | Jun 5, 2020 | regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_c... |
| CVE-2020-11492 | HIGH | 7.8 | 0.9% | Jun 5, 2020 | An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe p... |
| CVE-2020-10878 | HIGH | 8.6 | 4.9% | Jun 5, 2020 | Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A craft... |
| CVE-2020-10543 | HIGH | 8.2 | 11.3% | Jun 5, 2020 | Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers... |
| CVE-2020-13842 | HIGH | 7.8 | 0.1% | Jun 5, 2020 | An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). A dangerous AT com... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now