2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10936 | HIGH | 7.8 | 0.5% | May 27, 2020 | Sympa before 6.2.56 allows privilege escalation. |
| CVE-2020-6774 | HIGH | 8.8 | 0.3% | May 27, 2020 | Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attack... |
| CVE-2020-13630 | HIGH | 7 | 1.0% | May 27, 2020 | ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature. |
| CVE-2020-4379 | HIGH | 7.5 | 0.8% | May 27, 2020 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attack... |
| CVE-2020-4350 | HIGH | 7.5 | 0.8% | May 27, 2020 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attack... |
| CVE-2020-4349 | HIGH | 7.5 | 0.8% | May 27, 2020 | IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attack... |
| CVE-2020-4226 | HIGH | 7.5 | 1.3% | May 27, 2020 | IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to info... |
| CVE-2020-13386 | HIGH | 7.3 | 0.3% | May 27, 2020 | In SmartDraw 2020 27.0.0.0, the installer gives inherited write permissions to the Authenticated Users group on the Smar... |
| CVE-2020-13623 | HIGH | 7.5 | 1.2% | May 27, 2020 | JerryScript 2.2.0 allows attackers to cause a denial of service (stack consumption) via a proxy operation. |
| CVE-2020-13622 | HIGH | 7.5 | 1.3% | May 27, 2020 | JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a P... |
| CVE-2020-9046 | HIGH | 7.8 | 0.3% | May 26, 2020 | A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user ... |
| CVE-2020-6830 | HIGH | 7.5 | 0.9% | May 26, 2020 | For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridgin... |
| CVE-2020-12391 | HIGH | 7.5 | 1.4% | May 26, 2020 | Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed t... |
| CVE-2020-12387 | HIGH | 8.1 | 1.4% | May 26, 2020 | A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a pot... |
| CVE-2020-12393 | HIGH | 7.8 | 1.0% | May 26, 2020 | The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be c... |
| CVE-2020-8168 | HIGH | 8.8 | 0.7% | May 26, 2020 | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie... |
| CVE-2020-3811 | HIGH | 7.5 | 1.8% | May 26, 2020 | qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability. |
| CVE-2020-13482 | HIGH | 7.4 | 0.9% | May 25, 2020 | EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-m... |
| CVE-2020-13458 | HIGH | 8.8 | 0.5% | May 25, 2020 | An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear... |
| CVE-2020-13425 | HIGH | 7.1 | 0.6% | May 23, 2020 | TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a... |
| CVE-2020-13415 | HIGH | 7.5 | 0.7% | May 22, 2020 | An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity... |
| CVE-2020-13414 | HIGH | 7.5 | 1.5% | May 22, 2020 | An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software. |
| CVE-2020-13412 | HIGH | 8.8 | 0.6% | May 22, 2020 | An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token ... |
| CVE-2020-13398 | HIGH | 8.3 | 2.4% | May 22, 2020 | An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_... |
| CVE-2020-13396 | HIGH | 7.1 | 2.4% | May 22, 2020 | An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_rea... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now