2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4231 | MEDIUM | 6.5 | 0.8% | May 28, 2020 | IBM Security Identity Governance and Intelligence 5.2.6 could allow an authenticated user to perform unauthorized comman... |
| CVE-2020-13649 | HIGH | 7.5 | 2.1% | May 28, 2020 | parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated b... |
| CVE-2020-13362 | LOW | 3.2 | 0.4% | May 28, 2020 | In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue... |
| CVE-2020-7812 | CRITICAL | 9.8 | 0.7% | May 28, 2020 | Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allo... |
| CVE-2020-13361 | LOW | 3.9 | 0.4% | May 28, 2020 | In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which ... |
| CVE-2020-11950 | HIGH | 8.8 | 2.7% | May 28, 2020 | VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user... |
| CVE-2020-11949 | MEDIUM | 6.5 | 1.2% | May 28, 2020 | testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXX... |
| CVE-2020-13645 | MEDIUM | 6.5 | 1.9% | May 28, 2020 | In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the s... |
| CVE-2020-13644 | MEDIUM | 5.4 | 0.8% | May 28, 2020 | An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax... |
| CVE-2020-13643 | HIGH | 8.8 | 0.8% | May 28, 2020 | An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did ... |
| CVE-2020-13642 | HIGH | 8.8 | 0.8% | May 28, 2020 | An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content f... |
| CVE-2020-13641 | HIGH | 8.8 | 0.8% | May 28, 2020 | An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page functi... |
| CVE-2020-8606 | CRITICAL | 9.8 | 72.7% | May 27, 2020 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authent... |
| CVE-2020-8605 | HIGH | 8.8 | 87.6% | May 27, 2020 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitr... |
| CVE-2020-8604 | HIGH | 7.5 | 89.7% | May 27, 2020 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensi... |
| CVE-2020-8603 | MEDIUM | 6.1 | 2.0% | May 27, 2020 | A cross-site scripting vulnerability (XSS) in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow a remot... |
| CVE-2020-11075 | CRITICAL | 9.9 | 1.8% | May 27, 2020 | In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to t... |
| CVE-2020-11059 | HIGH | 7.5 | 1.1% | May 27, 2020 | In AEgir greater than or equal to 21.7.0 and less than 21.10.1, aegir publish and aegir build may leak secrets from envi... |
| CVE-2020-10936 | HIGH | 7.8 | 0.5% | May 27, 2020 | Sympa before 6.2.56 allows privilege escalation. |
| CVE-2020-6774 | HIGH | 8.8 | 0.3% | May 27, 2020 | Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attack... |
| CVE-2020-13633 | MEDIUM | 6.1 | 0.7% | May 27, 2020 | Fork before 5.8.3 allows XSS via navigation_title or title. |
| CVE-2020-13628 | MEDIUM | 6.1 | 2.2% | May 27, 2020 | Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId... |
| CVE-2020-13627 | MEDIUM | 6.1 | 2.2% | May 27, 2020 | Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId... |
| CVE-2020-10946 | MEDIUM | 6.1 | 2.2% | May 27, 2020 | Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page par... |
| CVE-2020-10945 | MEDIUM | 4.3 | 0.6% | May 27, 2020 | Centreon before 19.10.7 exposes Session IDs in server responses. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now