2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13112 | CRITICAL | 9.1 | 2.7% | May 21, 2020 | An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to inf... |
| CVE-2020-6471 | CRITICAL | 9.6 | 1.4% | May 21, 2020 | Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convin... |
| CVE-2020-6469 | CRITICAL | 9.6 | 1.2% | May 21, 2020 | Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convin... |
| CVE-2020-6466 | CRITICAL | 9.6 | 1.6% | May 21, 2020 | Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the rendere... |
| CVE-2020-6465 | CRITICAL | 9.6 | 1.6% | May 21, 2020 | Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compro... |
| CVE-2020-6462 | CRITICAL | 9.6 | 1.4% | May 21, 2020 | Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised ... |
| CVE-2020-6461 | CRITICAL | 9.6 | 1.2% | May 21, 2020 | Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the rend... |
| CVE-2020-6457 | CRITICAL | 9.6 | 1.2% | May 21, 2020 | Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially per... |
| CVE-2020-1955 | CRITICAL | 9.8 | 1.8% | May 20, 2020 | CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server... |
| CVE-2020-11716 | CRITICAL | 9.8 | 1.4% | May 20, 2020 | Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the... |
| CVE-2020-9409 | CRITICAL | 9.8 | 3.4% | May 20, 2020 | The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS ... |
| CVE-2020-12835 | CRITICAL | 9.8 | 11.7% | May 20, 2020 | An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an un... |
| CVE-2020-13226 | CRITICAL | 9.8 | 2.1% | May 20, 2020 | WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibil... |
| CVE-2020-9753 | CRITICAL | 9.1 | 1.1% | May 20, 2020 | Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer. |
| CVE-2020-13167 | CRITICAL | 9.8 | 95.4% | May 19, 2020 | Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain... |
| CVE-2020-13166 | CRITICAL | 9.8 | 77.6% | May 19, 2020 | The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod... |
| CVE-2020-11715 | CRITICAL | 9.8 | 1.4% | May 19, 2020 | Panasonic P99 devices through 2020-04-10 have Incorrect Access Control. NOTE: the vendor states that all affected produc... |
| CVE-2020-8434 | CRITICAL | 9.8 | 1.3% | May 19, 2020 | Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch ... |
| CVE-2020-1897 | CRITICAL | 9.8 | 1.1% | May 18, 2020 | A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invok... |
| CVE-2020-12258 | CRITICAL | 9.1 | 1.7% | May 18, 2020 | rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application... |
| CVE-2020-12856 | CRITICAL | 9.8 | 5.1% | May 18, 2020 | OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Andro... |
| CVE-2020-13126 | CRITICAL | 9.9 | 8.6% | May 17, 2020 | An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in ... |
| CVE-2020-13118 | CRITICAL | 9.8 | 4.0% | May 16, 2020 | An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community... |
| CVE-2020-13109 | CRITICAL | 9.8 | 4.8% | May 16, 2020 | Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted... |
| CVE-2020-8149 | CRITICAL | 9.8 | 2.0% | May 15, 2020 | Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before ve... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now