2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14988 | MEDIUM | 5.4 | 0.6% | Mar 11, 2021 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page vi... |
| CVE-2020-14987 | HIGH | 7.2 | 3.5% | Mar 11, 2021 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to exec... |
| CVE-2020-5025 | HIGH | 7.8 | 0.6% | Mar 11, 2021 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to... |
| CVE-2020-5024 | HIGH | 7.5 | 2.0% | Mar 11, 2021 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthe... |
| CVE-2020-4976 | MEDIUM | 4.4 | 0.3% | Mar 11, 2021 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us... |
| CVE-2020-1900 | CRITICAL | 9.8 | 1.4% | Mar 11, 2021 | When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property arr... |
| CVE-2020-1899 | HIGH | 7.5 | 1.2% | Mar 11, 2021 | The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This ... |
| CVE-2020-1898 | HIGH | 7.5 | 1.2% | Mar 11, 2021 | The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a maliciously constructe... |
| CVE-2020-15260 | MEDIUM | 6.8 | 1.0% | Mar 10, 2021 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto... |
| CVE-2020-35233 | MEDIUM | 6.5 | 0.6% | Mar 10, 2021 | The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external... |
| CVE-2020-35232 | — | — | — | Mar 10, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-35782. Reason: This candidate is a reservation d... |
| CVE-2020-35231 | HIGH | 8.8 | 1.1% | Mar 10, 2021 | The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue ... |
| CVE-2020-35230 | MEDIUM | 6.8 | 0.4% | Mar 10, 2021 | Multiple integer overflow parameters were found in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 d... |
| CVE-2020-35229 | HIGH | 8.8 | 0.8% | Mar 10, 2021 | The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not p... |
| CVE-2020-35228 | MEDIUM | 4.8 | 0.8% | Mar 10, 2021 | A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 device... |
| CVE-2020-35227 | HIGH | 7.2 | 1.1% | Mar 10, 2021 | A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the adm... |
| CVE-2020-35226 | HIGH | 7.1 | 0.6% | Mar 10, 2021 | NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sendi... |
| CVE-2020-35225 | MEDIUM | 6.8 | 0.6% | Mar 10, 2021 | The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length o... |
| CVE-2020-35224 | MEDIUM | 6.5 | 0.7% | Mar 10, 2021 | A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 device... |
| CVE-2020-35223 | HIGH | 8.8 | 0.6% | Mar 10, 2021 | The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices... |
| CVE-2020-35222 | — | — | — | Mar 10, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-35783. Reason: This candidate is a reservation d... |
| CVE-2020-35221 | HIGH | 8.8 | 0.5% | Mar 10, 2021 | The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was fo... |
| CVE-2020-35220 | — | — | — | Mar 10, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-35801. Reason: This candidate is a reservation d... |
| CVE-2020-27632 | HIGH | 7.5 | 1.2% | Mar 10, 2021 | In SIMATIC MV400 family versions prior to v7.0.6, the ISN generator is initialized with a constant value and has constan... |
| CVE-2020-19419 | HIGH | 7.5 | 3.0% | Mar 10, 2021 | Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive devic... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now