As reported by Google 's Project Zero team , 11 zero-day vulnerabilities were identified, which were exploited by malicious actors, in the first half of 2020.

This number indicates that 2020 will likely see the same amount of zero days as 2019, as Google security researchers discovered 20 such vulnerabilities last year.
Details about these vulnerabilities have been taken from a spreadsheet maintained by Google security researchers. The spreadsheet contains Google's internal statistics on zero-day exploitation since 2014, when the company began tracking the statistics.
Below you can see the current zero day vulnerabilities.

1. Firefox (CVE-2019-17026)
This vulnerability was used in conjunction with another zero day. It was fixed here, in Firefox 72.0.1.
2. Internet Explorer (CVE-2020-0674)
Along with the two Firefox, this vulnerability was exploited by a hacking group known as DarkHotel, believed to operate from the Korean peninsula. It was patched here.
3. Chrome (CVE-2020-6418)
This zero-day was discovered by Threat Analysis Group , but details about the attacks in which it was used were never released. It was fixed here, in Chrome version 80.0.3987.122.
4. & 5. Trend Micro OfficeScan (CVE-2020-8467 and CVE-2020-8468)
Both vulnerabilities were discovered internally by Trend Micro. They are believed to have been discovered while Trend Micro was investigating a 2019 zero-day in the same product used to hack Mitsubishi Electric. Fixed here.
6. & 7. Firefox (CVE-2020-6819 and CVE-2020-6820)
Details of the attacks using these two Firefox vulnerabilities have not yet been released, although security researchers have suggested that they may be part of a wider exploit chain. Fixed here, in Firefox 74.0.1.
8. & 9. & 10. (CVE-2020-0938, CVE-2020-1020, and CVE-2020-1027)
All three bugs were discovered and reported to Microsoft by Google TAG, and like most Google TAG discoveries, no details have been released about them yet. They were fixed here, here , and here, in Microsoft's April 2020 Patch Tuesday.
11. Sophos XG Firewall (CVE 2020-12271)
A group of hackers discovered a zero-day earlier this year in XG, a firewall product developed by British security firm Sophos. It was fixed here.
