2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-1162HIGH7.8An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain o...
CVE-2020-1160MEDIUM5.5An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects ...
CVE-2020-1148MEDIUM5.4A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requ...
CVE-2020-1120MEDIUM5.5A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file o...
CVE-2020-1073HIGH8.1A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, ...
CVE-2020-0986HIGH7.8An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '...
CVE-2020-0916HIGH7.8An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec...
CVE-2020-0915HIGH7.8An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec...
CVE-2020-7456MEDIUM6.8In FreeBSD 12.1-STABLE before r361918, 12.1-RELEASE before p6, 11.4-STABLE before r361919, 11.3-RELEASE before p10, and ...
CVE-2020-6265CRITICAL9.8SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an...
CVE-2020-13911MEDIUM5.4Your Online Shop 1.8.0 allows authenticated users to trigger XSS via a Change Name or Change Surname operation.
CVE-2020-13872HIGH8.8Royal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel authentication via a brut...
CVE-2020-11957HIGH7.5The Bluetooth Low Energy implementation in Cypress PSoC Creator BLE 4.2 component versions before 3.64 generates a rando...
CVE-2020-13892MEDIUM5.4The SportsPress plugin before 2.7.2 for WordPress allows XSS.
CVE-2020-12004HIGH7.5The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior ...
CVE-2020-12000HIGH7.5The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validat...
CVE-2020-10644HIGH7.5The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted dat...
CVE-2020-9858HIGH7.8A dynamic library loading issue was addressed with improved path searching. This issue is fixed in Windows Migration Ass...
CVE-2020-9856MEDIUM5.3This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able...
CVE-2020-9855HIGH7.8A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. T...
CVE-2020-9852HIGH7.8An integer overflow was addressed through improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, ma...
CVE-2020-9851MEDIUM5.5An access issue was addressed with improved access restrictions. This issue is fixed in macOS Catalina 10.15.5. A malici...
CVE-2020-9850CRITICAL9.8A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, wa...
CVE-2020-9848LOW2.4An authorization issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5. A ...
CVE-2020-9847HIGH8.6An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A mali...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now