2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35792 | MEDIUM | 6.8 | 0.7% | Dec 30, 2020 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7500v2 before 1.0.3.48... |
| CVE-2020-35791 | MEDIUM | 6.7 | 0.5% | Dec 30, 2020 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.68, ... |
| CVE-2020-35790 | MEDIUM | 6.8 | 0.7% | Dec 30, 2020 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.56, ... |
| CVE-2020-35789 | HIGH | 8.8 | 2.7% | Dec 30, 2020 | NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user. |
| CVE-2020-35788 | MEDIUM | 6.8 | 0.4% | Dec 30, 2020 | NETGEAR WAC104 devices before 1.0.4.13 are affected by a buffer overflow by an authenticated user. |
| CVE-2020-35787 | HIGH | 8 | 0.5% | Dec 30, 2020 | Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D3600 before 1.0.0.76, ... |
| CVE-2020-35786 | MEDIUM | 4.5 | 0.5% | Dec 30, 2020 | NETGEAR R7800 devices before 1.0.2.74 are affected by a buffer overflow by an authenticated user. |
| CVE-2020-35785 | HIGH | 8.8 | 0.7% | Dec 30, 2020 | NETGEAR DGN2200v1 devices before v1.0.0.60 mishandle HTTPd authentication (aka PSV-2020-0363, PSV-2020-0364, and PSV-202... |
| CVE-2020-35784 | HIGH | 7.2 | 0.8% | Dec 30, 2020 | Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0... |
| CVE-2020-35783 | MEDIUM | 6.5 | 1.5% | Dec 30, 2020 | Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0... |
| CVE-2020-35782 | HIGH | 8.1 | 1.6% | Dec 30, 2020 | Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0... |
| CVE-2020-35781 | MEDIUM | 6.5 | 0.8% | Dec 30, 2020 | NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service. |
| CVE-2020-35780 | MEDIUM | 6.5 | 0.8% | Dec 30, 2020 | NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service. |
| CVE-2020-35779 | HIGH | 8.6 | 0.9% | Dec 30, 2020 | NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service. |
| CVE-2020-35778 | HIGH | 8.8 | 0.4% | Dec 30, 2020 | Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36. |
| CVE-2020-35777 | HIGH | 8.4 | 0.8% | Dec 30, 2020 | NETGEAR DGN2200v1 devices before v1.0.0.58 are affected by command injection. |
| CVE-2020-10209 | HIGH | 8.1 | 2.7% | Dec 30, 2020 | Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx ser... |
| CVE-2020-10208 | CRITICAL | 9.9 | 4.1% | Dec 30, 2020 | Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, A... |
| CVE-2020-10206 | MEDIUM | 4.4 | 0.3% | Dec 30, 2020 | Use of a Hard-coded Password in VNCserver in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx seri... |
| CVE-2020-10210 | CRITICAL | 9.8 | 1.5% | Dec 29, 2020 | Because of hard-coded SSH keys for the root user in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6... |
| CVE-2020-10207 | CRITICAL | 9.8 | 2.5% | Dec 29, 2020 | Use of Hard-coded Credentials in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6... |
| CVE-2020-10148 | CRITICAL | 9.8 | 92.0% | Dec 29, 2020 | The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API com... |
| CVE-2020-27645 | HIGH | 8.8 | 1.2% | Dec 29, 2020 | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\... |
| CVE-2020-27644 | HIGH | 8.8 | 1.2% | Dec 29, 2020 | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\... |
| CVE-2020-27643 | MEDIUM | 6.5 | 1.4% | Dec 29, 2020 | The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local u... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now