2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13438 | MEDIUM | 6.5 | 0.8% | May 24, 2020 | ffjpeg through 2020-02-24 has an invalid read in jfif_encode in jfif.c. |
| CVE-2020-13435 | MEDIUM | 5.5 | 0.6% | May 24, 2020 | SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c. |
| CVE-2020-13434 | MEDIUM | 5.5 | 1.0% | May 24, 2020 | SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c. |
| CVE-2020-13433 | CRITICAL | 9.8 | 1.1% | May 24, 2020 | Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter. |
| CVE-2020-13430 | MEDIUM | 6.1 | 1.7% | May 24, 2020 | Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource. |
| CVE-2020-13429 | MEDIUM | 5.4 | 0.7% | May 24, 2020 | legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (... |
| CVE-2020-13425 | HIGH | 7.1 | 0.6% | May 23, 2020 | TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a... |
| CVE-2020-13424 | MEDIUM | 6.5 | 1.7% | May 23, 2020 | The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure. |
| CVE-2020-13417 | CRITICAL | 9.8 | 2.3% | May 22, 2020 | An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CV... |
| CVE-2020-13416 | MEDIUM | 6.5 | 0.5% | May 22, 2020 | An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is no... |
| CVE-2020-13415 | HIGH | 7.5 | 0.7% | May 22, 2020 | An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity... |
| CVE-2020-13414 | HIGH | 7.5 | 1.5% | May 22, 2020 | An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software. |
| CVE-2020-13413 | MEDIUM | 5.3 | 1.4% | May 22, 2020 | An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API,... |
| CVE-2020-13412 | HIGH | 8.8 | 0.6% | May 22, 2020 | An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token ... |
| CVE-2020-12397 | MEDIUM | 4.3 | 0.6% | May 22, 2020 | By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address t... |
| CVE-2020-13398 | HIGH | 8.3 | 2.4% | May 22, 2020 | An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_... |
| CVE-2020-13397 | MEDIUM | 5.5 | 0.5% | May 22, 2020 | An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security... |
| CVE-2020-13396 | HIGH | 7.1 | 2.4% | May 22, 2020 | An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_rea... |
| CVE-2020-13394 | CRITICAL | 9.8 | 2.6% | May 22, 2020 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42... |
| CVE-2020-13393 | CRITICAL | 9.8 | 3.3% | May 22, 2020 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42... |
| CVE-2020-13392 | CRITICAL | 9.8 | 2.6% | May 22, 2020 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42... |
| CVE-2020-13391 | CRITICAL | 9.8 | 2.6% | May 22, 2020 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42... |
| CVE-2020-13390 | CRITICAL | 9.8 | 2.6% | May 22, 2020 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42... |
| CVE-2020-13389 | CRITICAL | 9.8 | 2.6% | May 22, 2020 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42... |
| CVE-2020-13388 | CRITICAL | 9.8 | 4.4% | May 22, 2020 | An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Pyt... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now