2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0963 | MEDIUM | 5.5 | 5.5% | May 21, 2020 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m... |
| CVE-2020-0909 | HIGH | 7.5 | 4.4% | May 21, 2020 | A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted net... |
| CVE-2020-0901 | CRITICAL | 9.8 | 11.6% | May 21, 2020 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2020-7808 | CRITICAL | 9.8 | 0.7% | May 21, 2020 | In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js)... |
| CVE-2020-13258 | MEDIUM | 6.1 | 2.5% | May 21, 2020 | Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.p... |
| CVE-2020-13113 | HIGH | 8.2 | 1.9% | May 21, 2020 | An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to c... |
| CVE-2020-12828 | CRITICAL | 9.8 | 3.3% | May 21, 2020 | An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations o... |
| CVE-2020-12431 | MEDIUM | 6.6 | 0.5% | May 21, 2020 | A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on t... |
| CVE-2020-13114 | HIGH | 7.5 | 2.3% | May 21, 2020 | An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead ... |
| CVE-2020-13112 | CRITICAL | 9.1 | 2.7% | May 21, 2020 | An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to inf... |
| CVE-2020-10738 | HIGH | 8.8 | 3.1% | May 21, 2020 | A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier... |
| CVE-2020-9069 | MEDIUM | 6.5 | 0.3% | May 21, 2020 | There is an information leakage vulnerability in some Huawei products. An unauthenticated, adjacent attacker could explo... |
| CVE-2020-9045 | MEDIUM | 6.5 | 1.0% | May 21, 2020 | During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System ... |
| CVE-2020-8572 | HIGH | 7.5 | 1.3% | May 21, 2020 | Element OS prior to version 12.0 and Element HealthTools prior to version 2020.04.01.04 are susceptible to a vulnerabili... |
| CVE-2020-7655 | MEDIUM | 6.1 | 0.8% | May 21, 2020 | netius prior to 1.17.58 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks mi... |
| CVE-2020-5752 | HIGH | 7.8 | 8.6% | May 21, 2020 | Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra... |
| CVE-2020-1799 | HIGH | 7.5 | 0.4% | May 21, 2020 | E6878-370 with versions of 10.0.3.1(H557SP27C233), 10.0.3.1(H563SP1C00), 10.0.3.1(H563SP1C233) has a use after free vuln... |
| CVE-2020-6491 | MEDIUM | 6.5 | 1.5% | May 21, 2020 | Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spo... |
| CVE-2020-6490 | MEDIUM | 4.3 | 1.5% | May 21, 2020 | Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been abl... |
| CVE-2020-6489 | MEDIUM | 4.3 | 1.6% | May 21, 2020 | Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had... |
| CVE-2020-6488 | MEDIUM | 4.3 | 1.5% | May 21, 2020 | Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass ... |
| CVE-2020-6487 | MEDIUM | 6.5 | 1.6% | May 21, 2020 | Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass ... |
| CVE-2020-6486 | MEDIUM | 6.5 | 1.7% | May 21, 2020 | Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypas... |
| CVE-2020-6485 | MEDIUM | 6.5 | 1.7% | May 21, 2020 | Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had co... |
| CVE-2020-6484 | MEDIUM | 6.5 | 1.5% | May 21, 2020 | Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now