2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12390 | CRITICAL | 9.8 | 1.6% | May 26, 2020 | Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability a... |
| CVE-2020-12389 | CRITICAL | 10 | 1.7% | May 26, 2020 | The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note... |
| CVE-2020-12388 | CRITICAL | 10 | 2.7% | May 26, 2020 | The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note... |
| CVE-2020-12396 | CRITICAL | 9.8 | 1.7% | May 26, 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed ev... |
| CVE-2020-12395 | CRITICAL | 9.8 | 2.3% | May 26, 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of... |
| CVE-2020-8171 | CRITICAL | 9.8 | 3.9% | May 26, 2020 | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie... |
| CVE-2020-13485 | CRITICAL | 9.1 | 1.4% | May 25, 2020 | The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header. |
| CVE-2020-13442 | CRITICAL | 9.8 | 2.6% | May 25, 2020 | A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP f... |
| CVE-2020-5537 | CRITICAL | 9.8 | 2.9% | May 25, 2020 | Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors. |
| CVE-2020-13433 | CRITICAL | 9.8 | 1.1% | May 24, 2020 | Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter. |
| CVE-2020-13417 | CRITICAL | 9.8 | 2.3% | May 22, 2020 | An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CV... |
| CVE-2020-13394 | CRITICAL | 9.8 | 2.6% | May 22, 2020 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42... |
| CVE-2020-13393 | CRITICAL | 9.8 | 3.3% | May 22, 2020 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42... |
| CVE-2020-13392 | CRITICAL | 9.8 | 2.6% | May 22, 2020 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42... |
| CVE-2020-13391 | CRITICAL | 9.8 | 2.6% | May 22, 2020 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42... |
| CVE-2020-13390 | CRITICAL | 9.8 | 2.6% | May 22, 2020 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42... |
| CVE-2020-13389 | CRITICAL | 9.8 | 2.6% | May 22, 2020 | An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42... |
| CVE-2020-13388 | CRITICAL | 9.8 | 4.4% | May 22, 2020 | An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Pyt... |
| CVE-2020-7813 | CRITICAL | 9.8 | 0.7% | May 22, 2020 | Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allo... |
| CVE-2020-6091 | CRITICAL | 9.1 | 2.3% | May 22, 2020 | An exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN... |
| CVE-2020-3280 | CRITICAL | 9.8 | 6.9% | May 22, 2020 | A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allo... |
| CVE-2020-1112 | CRITICAL | 9.9 | 3.7% | May 21, 2020 | An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS modul... |
| CVE-2020-0901 | CRITICAL | 9.8 | 11.6% | May 21, 2020 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2020-7808 | CRITICAL | 9.8 | 0.7% | May 21, 2020 | In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js)... |
| CVE-2020-12828 | CRITICAL | 9.8 | 3.3% | May 21, 2020 | An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations o... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now