2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26289HIGH7.5date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular ...
CVE-2020-24360HIGH7.4An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issu...
CVE-2020-15898MEDIUM5.3In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability...
CVE-2020-26569MEDIUM5.9In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result ...
CVE-2020-35627HIGH8.8Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that ca...
CVE-2020-29245MEDIUM6.5dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData.
CVE-2020-29244MEDIUM6.5dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame.
CVE-2020-29243MEDIUM6.5dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame.
CVE-2020-29242MEDIUM6.5dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame.
CVE-2020-29160HIGH7.5An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a wa...
CVE-2020-29159MEDIUM4.9An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Ro...
CVE-2020-29158MEDIUM4.3An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access...
CVE-2020-26035MEDIUM5.4An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.
CVE-2020-26034MEDIUM4.3An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a wa...
CVE-2020-26033MEDIUM5.4An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF tok...
CVE-2020-26032HIGH7.5An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in...
CVE-2020-26031MEDIUM4.3An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base ...
CVE-2020-26030CRITICAL9.8An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted head...
CVE-2020-26029MEDIUM6.5An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On...
CVE-2020-26028MEDIUM4.9An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.
CVE-2020-29194HIGH7.5Panasonic Security System WV-S2231L 4.25 allows a denial of service of the admin control panel (which will require a phy...
CVE-2020-29193MEDIUM6.8Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which is just the asdf keyboa...
CVE-2020-28096MEDIUM6.8FOSCAM FHD X1 1.14.2.4 devices allow attackers (with physical UART access) to login via the ipc.fos~ password.
CVE-2020-28094HIGH7.5On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, the default settings for the router speed test contain links to d...
CVE-2020-28093HIGH7.2On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now