2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-0963MEDIUM5.5An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m...
CVE-2020-0909HIGH7.5A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted net...
CVE-2020-0901CRITICAL9.8A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje...
CVE-2020-7808CRITICAL9.8In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js)...
CVE-2020-13258MEDIUM6.1Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.p...
CVE-2020-13113HIGH8.2An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to c...
CVE-2020-12828CRITICAL9.8An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations o...
CVE-2020-12431MEDIUM6.6A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on t...
CVE-2020-13114HIGH7.5An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead ...
CVE-2020-13112CRITICAL9.1An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to inf...
CVE-2020-10738HIGH8.8A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier...
CVE-2020-9069MEDIUM6.5There is an information leakage vulnerability in some Huawei products. An unauthenticated, adjacent attacker could explo...
CVE-2020-9045MEDIUM6.5During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System ...
CVE-2020-8572HIGH7.5Element OS prior to version 12.0 and Element HealthTools prior to version 2020.04.01.04 are susceptible to a vulnerabili...
CVE-2020-7655MEDIUM6.1netius prior to 1.17.58 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks mi...
CVE-2020-5752HIGH7.8Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra...
CVE-2020-1799HIGH7.5E6878-370 with versions of 10.0.3.1(H557SP27C233), 10.0.3.1(H563SP1C00), 10.0.3.1(H563SP1C233) has a use after free vuln...
CVE-2020-6491MEDIUM6.5Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spo...
CVE-2020-6490MEDIUM4.3Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been abl...
CVE-2020-6489MEDIUM4.3Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had...
CVE-2020-6488MEDIUM4.3Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass ...
CVE-2020-6487MEDIUM6.5Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass ...
CVE-2020-6486MEDIUM6.5Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypas...
CVE-2020-6485MEDIUM6.5Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had co...
CVE-2020-6484MEDIUM6.5Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now