2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35792MEDIUM6.8Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7500v2 before 1.0.3.48...
CVE-2020-35791MEDIUM6.7Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.68, ...
CVE-2020-35790MEDIUM6.8Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.56, ...
CVE-2020-35789HIGH8.8NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.
CVE-2020-35788MEDIUM6.8NETGEAR WAC104 devices before 1.0.4.13 are affected by a buffer overflow by an authenticated user.
CVE-2020-35787HIGH8Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D3600 before 1.0.0.76, ...
CVE-2020-35786MEDIUM4.5NETGEAR R7800 devices before 1.0.2.74 are affected by a buffer overflow by an authenticated user.
CVE-2020-35785HIGH8.8NETGEAR DGN2200v1 devices before v1.0.0.60 mishandle HTTPd authentication (aka PSV-2020-0363, PSV-2020-0364, and PSV-202...
CVE-2020-35784HIGH7.2Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0...
CVE-2020-35783MEDIUM6.5Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0...
CVE-2020-35782HIGH8.1Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0...
CVE-2020-35781MEDIUM6.5NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service.
CVE-2020-35780MEDIUM6.5NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service.
CVE-2020-35779HIGH8.6NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service.
CVE-2020-35778HIGH8.8Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36.
CVE-2020-35777HIGH8.4NETGEAR DGN2200v1 devices before v1.0.0.58 are affected by command injection.
CVE-2020-10209HIGH8.1Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx ser...
CVE-2020-10208CRITICAL9.9Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, A...
CVE-2020-10206MEDIUM4.4Use of a Hard-coded Password in VNCserver in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx seri...
CVE-2020-10210CRITICAL9.8Because of hard-coded SSH keys for the root user in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6...
CVE-2020-10207CRITICAL9.8Use of Hard-coded Credentials in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6...
CVE-2020-10148CRITICAL9.8The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API com...
CVE-2020-27645HIGH8.8The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\...
CVE-2020-27644HIGH8.8The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\...
CVE-2020-27643MEDIUM6.5The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local u...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now