2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14040 | HIGH | 7.5 | 1.9% | Jun 17, 2020 | The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder ent... |
| CVE-2020-6869 | HIGH | 8.1 | 0.9% | Jun 17, 2020 | All versions up to 10.06 of ZTEMarket APK are impacted by an information leak vulnerability. Due to Activity Component e... |
| CVE-2020-4532 | MEDIUM | 5.3 | 1.3% | Jun 17, 2020 | IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.... |
| CVE-2020-9332 | HIGH | 7.8 | 0.5% | Jun 17, 2020 | ftusbbus2.sys in FabulaTech USB for Remote Desktop through 2020-02-19 allows privilege escalation via crafted IoCtl code... |
| CVE-2020-7932 | MEDIUM | 5.7 | 0.8% | Jun 17, 2020 | OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query paramet... |
| CVE-2020-6752 | LOW | 3.8 | 0.6% | Jun 17, 2020 | In OMERO before 5.6.1, group owners can access members' data in other groups. |
| CVE-2020-13637 | HIGH | 7.5 | 0.6% | Jun 17, 2020 | An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms... |
| CVE-2020-14405 | MEDIUM | 6.5 | 1.9% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size. |
| CVE-2020-14404 | MEDIUM | 5.4 | 1.6% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings. |
| CVE-2020-14403 | MEDIUM | 5.4 | 1.6% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings. |
| CVE-2020-14402 | MEDIUM | 5.4 | 1.9% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings. |
| CVE-2020-14401 | MEDIUM | 6.5 | 2.4% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow. |
| CVE-2020-14400 | HIGH | 7.5 | 2.8% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvnc... |
| CVE-2020-14399 | HIGH | 7.5 | 2.8% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvnc... |
| CVE-2020-14398 | HIGH | 7.5 | 2.8% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in li... |
| CVE-2020-14397 | HIGH | 7.5 | 3.4% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference. |
| CVE-2020-14396 | HIGH | 7.5 | 2.6% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference. |
| CVE-2020-14295 | HIGH | 7.2 | 86.3% | Jun 17, 2020 | A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead... |
| CVE-2020-12827 | HIGH | 7.2 | 2.7% | Jun 17, 2020 | MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML docu... |
| CVE-2020-10747 | — | — | — | Jun 17, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-13224 | HIGH | 8.8 | 2.2% | Jun 17, 2020 | TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.... |
| CVE-2020-11914 | MEDIUM | 4.3 | 1.7% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read. |
| CVE-2020-11913 | MEDIUM | 5.3 | 3.4% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. |
| CVE-2020-11912 | MEDIUM | 5.3 | 4.5% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read. |
| CVE-2020-11911 | MEDIUM | 5.3 | 3.1% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now