2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-0624HIGH7.8An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ...
CVE-2020-0623HIGH7.8An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka...
CVE-2020-0620HIGH7.8An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly handles files, aka 'Micr...
CVE-2020-0614HIGH7.8An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka...
CVE-2020-0613HIGH7.8An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka...
CVE-2020-0612HIGH7.5A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the...
CVE-2020-0611HIGH7.5A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious se...
CVE-2020-0606HIGH8.8A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a fi...
CVE-2020-0605HIGH8.8A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a fi...
CVE-2020-0603HIGH8.8A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memor...
CVE-2020-0602HIGH7.5A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of ...
CVE-2020-0601HIGH8.1A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c...
CVE-2020-7054HIGH8.8MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c in libIEC61850 through 1.4.0 has a heap-based buffer ov...
CVE-2020-7053HIGH7.8In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm through 4.19.96 (and 5.x before 5.2), there is a us...
CVE-2020-5509HIGH7.2PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile ima...
CVE-2020-5180HIGH7.8Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be use...
CVE-2020-6304HIGH7.5Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21,...
CVE-2020-5852HIGH7.5Undisclosed traffic patterns received may cause a disruption of service to the Traffic Management Microkernel (TMM). Thi...
CVE-2020-5196HIGH8.1Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create f...
CVE-2020-6949HIGH8.8A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can ...
CVE-2020-5390HIGH7.5PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is ef...
CVE-2020-6860HIGH8.8libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header mess...
CVE-2020-6851HIGH7.5OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack ...
CVE-2020-6377HIGH8.8Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap co...
CVE-2020-6757HIGH8.8contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now