2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15833 | CRITICAL | 9.8 | 1.6% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The Dropbear SSH daemon has been modified to... |
| CVE-2020-15832 | HIGH | 7.5 | 1.1% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The poof.cgi script contains undocumented co... |
| CVE-2020-13860 | HIGH | 7.5 | 1.1% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undo... |
| CVE-2020-13859 | CRITICAL | 9.8 | 1.2% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with ... |
| CVE-2020-13858 | CRITICAL | 9.8 | 1.4% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented ... |
| CVE-2020-13857 | HIGH | 7.5 | 1.1% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sendin... |
| CVE-2020-13856 | HIGH | 7.5 | 1.2% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download t... |
| CVE-2020-17380 | MEDIUM | 6.3 | 0.4% | Jan 30, 2021 | A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while... |
| CVE-2020-15690 | CRITICAL | 9.8 | 3.2% | Jan 30, 2021 | In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline characte... |
| CVE-2020-14418 | HIGH | 7 | 0.3% | Jan 30, 2021 | A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges t... |
| CVE-2020-15568 | CRITICAL | 9.8 | 29.2% | Jan 30, 2021 | TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic cla... |
| CVE-2020-29557 | CRITICAL | 9.8 | 54.3% | Jan 29, 2021 | An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web inter... |
| CVE-2020-24670 | MEDIUM | 5.4 | 0.6% | Jan 29, 2021 | The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerabilit... |
| CVE-2020-24669 | MEDIUM | 5.4 | 0.6% | Jan 29, 2021 | The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerabi... |
| CVE-2020-24666 | MEDIUM | 5.4 | 0.6% | Jan 29, 2021 | The Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a stored Cross-site scripting vulnerability, w... |
| CVE-2020-24665 | MEDIUM | 6.5 | 1.1% | Jan 29, 2021 | The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerabili... |
| CVE-2020-24664 | MEDIUM | 5.4 | 0.6% | Jan 29, 2021 | The dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerabilit... |
| CVE-2020-35652 | MEDIUM | 6.5 | 1.9% | Jan 29, 2021 | An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 1... |
| CVE-2020-35547 | CRITICAL | 9.1 | 1.1% | Jan 29, 2021 | A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to ga... |
| CVE-2020-35145 | HIGH | 7.8 | 0.6% | Jan 29, 2021 | Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerab... |
| CVE-2020-29605 | MEDIUM | 4.3 | 0.9% | Jan 29, 2021 | An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed t... |
| CVE-2020-29604 | MEDIUM | 6.5 | 1.1% | Jan 29, 2021 | An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (wit... |
| CVE-2020-29603 | MEDIUM | 4.3 | 1.1% | Jan 29, 2021 | In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' n... |
| CVE-2020-29538 | MEDIUM | 4.9 | 1.0% | Jan 29, 2021 | Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malic... |
| CVE-2020-29537 | MEDIUM | 5.4 | 0.8% | Jan 29, 2021 | Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potential... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now