2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11047 | MEDIUM | 5.9 | 1.7% | May 7, 2020 | In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A ma... |
| CVE-2020-11046 | LOW | 2.2 | 1.3% | May 7, 2020 | In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead t... |
| CVE-2020-11045 | LOW | 3.3 | 1.7% | May 7, 2020 | In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client me... |
| CVE-2020-11044 | LOW | 2.2 | 1.9% | May 7, 2020 | In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client appl... |
| CVE-2020-11042 | MEDIUM | 5.9 | 1.8% | May 7, 2020 | In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading... |
| CVE-2020-7805 | CRITICAL | 9.8 | 2.6% | May 7, 2020 | An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This i... |
| CVE-2020-7803 | HIGH | 8.8 | 1.2% | May 7, 2020 | IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donw... |
| CVE-2020-10974 | HIGH | 7.5 | 1.7% | May 7, 2020 | An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the... |
| CVE-2020-10973 | HIGH | 7.5 | 7.8% | May 7, 2020 | An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/Ex... |
| CVE-2020-10972 | HIGH | 7.5 | 1.7% | May 7, 2020 | An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source c... |
| CVE-2020-10971 | HIGH | 8.8 | 2.7% | May 7, 2020 | An issue was discovered on Wavlink Jetstream devices where a crafted POST request can be sent to adm.cgi that will resul... |
| CVE-2020-7646 | CRITICAL | 9.8 | 1.9% | May 7, 2020 | curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input. |
| CVE-2020-5751 | MEDIUM | 5.4 | 0.7% | May 7, 2020 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si... |
| CVE-2020-5750 | MEDIUM | 6.1 | 1.1% | May 7, 2020 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-... |
| CVE-2020-5749 | MEDIUM | 5.4 | 0.7% | May 7, 2020 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si... |
| CVE-2020-5748 | MEDIUM | 6.1 | 1.1% | May 7, 2020 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-... |
| CVE-2020-5747 | MEDIUM | 5.4 | 0.7% | May 7, 2020 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si... |
| CVE-2020-5746 | MEDIUM | 5.4 | 0.7% | May 7, 2020 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si... |
| CVE-2020-5745 | HIGH | 7.4 | 0.8% | May 7, 2020 | Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by trickin... |
| CVE-2020-5744 | MEDIUM | 4.9 | 1.4% | May 7, 2020 | Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files... |
| CVE-2020-5743 | MEDIUM | 4.3 | 0.8% | May 7, 2020 | Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadat... |
| CVE-2020-12679 | MEDIUM | 6.1 | 0.8% | May 7, 2020 | A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 befor... |
| CVE-2020-12608 | HIGH | 7.8 | 22.4% | May 7, 2020 | An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Moni... |
| CVE-2020-12448 | MEDIUM | 5.3 | 1.2% | May 7, 2020 | GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet. |
| CVE-2020-11431 | CRITICAL | 9.1 | 2.1% | May 7, 2020 | The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remot... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now