2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14988MEDIUM5.4An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page vi...
CVE-2020-14987HIGH7.2An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to exec...
CVE-2020-5025HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to...
CVE-2020-5024HIGH7.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthe...
CVE-2020-4976MEDIUM4.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us...
CVE-2020-1900CRITICAL9.8When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property arr...
CVE-2020-1899HIGH7.5The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This ...
CVE-2020-1898HIGH7.5The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a maliciously constructe...
CVE-2020-15260MEDIUM6.8PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto...
CVE-2020-35233MEDIUM6.5The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external...
CVE-2020-35232Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-35782. Reason: This candidate is a reservation d...
CVE-2020-35231HIGH8.8The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue ...
CVE-2020-35230MEDIUM6.8Multiple integer overflow parameters were found in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 d...
CVE-2020-35229HIGH8.8The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not p...
CVE-2020-35228MEDIUM4.8A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 device...
CVE-2020-35227HIGH7.2A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the adm...
CVE-2020-35226HIGH7.1NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sendi...
CVE-2020-35225MEDIUM6.8The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length o...
CVE-2020-35224MEDIUM6.5A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 device...
CVE-2020-35223HIGH8.8The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices...
CVE-2020-35222Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-35783. Reason: This candidate is a reservation d...
CVE-2020-35221HIGH8.8The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was fo...
CVE-2020-35220Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-35801. Reason: This candidate is a reservation d...
CVE-2020-27632HIGH7.5In SIMATIC MV400 family versions prior to v7.0.6, the ISN generator is initialized with a constant value and has constan...
CVE-2020-19419HIGH7.5Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive devic...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now