2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15833CRITICAL9.8An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The Dropbear SSH daemon has been modified to...
CVE-2020-15832HIGH7.5An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The poof.cgi script contains undocumented co...
CVE-2020-13860HIGH7.5An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undo...
CVE-2020-13859CRITICAL9.8An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with ...
CVE-2020-13858CRITICAL9.8An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented ...
CVE-2020-13857HIGH7.5An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sendin...
CVE-2020-13856HIGH7.5An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download t...
CVE-2020-17380MEDIUM6.3A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while...
CVE-2020-15690CRITICAL9.8In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline characte...
CVE-2020-14418HIGH7A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges t...
CVE-2020-15568CRITICAL9.8TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic cla...
CVE-2020-29557CRITICAL9.8An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web inter...
CVE-2020-24670MEDIUM5.4The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerabilit...
CVE-2020-24669MEDIUM5.4The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerabi...
CVE-2020-24666MEDIUM5.4The Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a stored Cross-site scripting vulnerability, w...
CVE-2020-24665MEDIUM6.5The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerabili...
CVE-2020-24664MEDIUM5.4The dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerabilit...
CVE-2020-35652MEDIUM6.5An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 1...
CVE-2020-35547CRITICAL9.1A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to ga...
CVE-2020-35145HIGH7.8Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerab...
CVE-2020-29605MEDIUM4.3An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed t...
CVE-2020-29604MEDIUM6.5An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (wit...
CVE-2020-29603MEDIUM4.3In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' n...
CVE-2020-29538MEDIUM4.9Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malic...
CVE-2020-29537MEDIUM5.4Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potential...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now