2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26289 | HIGH | 7.5 | 2.1% | Dec 28, 2020 | date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular ... |
| CVE-2020-24360 | HIGH | 7.4 | 0.7% | Dec 28, 2020 | An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issu... |
| CVE-2020-15898 | MEDIUM | 5.3 | 1.0% | Dec 28, 2020 | In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability... |
| CVE-2020-26569 | MEDIUM | 5.9 | 0.8% | Dec 28, 2020 | In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result ... |
| CVE-2020-35627 | HIGH | 8.8 | 2.0% | Dec 28, 2020 | Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that ca... |
| CVE-2020-29245 | MEDIUM | 6.5 | 1.1% | Dec 28, 2020 | dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData. |
| CVE-2020-29244 | MEDIUM | 6.5 | 1.1% | Dec 28, 2020 | dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame. |
| CVE-2020-29243 | MEDIUM | 6.5 | 1.1% | Dec 28, 2020 | dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame. |
| CVE-2020-29242 | MEDIUM | 6.5 | 1.1% | Dec 28, 2020 | dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame. |
| CVE-2020-29160 | HIGH | 7.5 | 0.9% | Dec 28, 2020 | An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a wa... |
| CVE-2020-29159 | MEDIUM | 4.9 | 0.9% | Dec 28, 2020 | An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Ro... |
| CVE-2020-29158 | MEDIUM | 4.3 | 0.7% | Dec 28, 2020 | An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access... |
| CVE-2020-26035 | MEDIUM | 5.4 | 0.5% | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket. |
| CVE-2020-26034 | MEDIUM | 4.3 | 0.7% | Dec 28, 2020 | An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a wa... |
| CVE-2020-26033 | MEDIUM | 5.4 | 0.4% | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF tok... |
| CVE-2020-26032 | HIGH | 7.5 | 1.1% | Dec 28, 2020 | An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in... |
| CVE-2020-26031 | MEDIUM | 4.3 | 0.6% | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base ... |
| CVE-2020-26030 | CRITICAL | 9.8 | 1.3% | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted head... |
| CVE-2020-26029 | MEDIUM | 6.5 | 0.8% | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On... |
| CVE-2020-26028 | MEDIUM | 4.9 | 0.9% | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets. |
| CVE-2020-29194 | HIGH | 7.5 | 1.2% | Dec 28, 2020 | Panasonic Security System WV-S2231L 4.25 allows a denial of service of the admin control panel (which will require a phy... |
| CVE-2020-29193 | MEDIUM | 6.8 | 0.4% | Dec 28, 2020 | Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which is just the asdf keyboa... |
| CVE-2020-28096 | MEDIUM | 6.8 | 0.5% | Dec 28, 2020 | FOSCAM FHD X1 1.14.2.4 devices allow attackers (with physical UART access) to login via the ipc.fos~ password. |
| CVE-2020-28094 | HIGH | 7.5 | 1.2% | Dec 28, 2020 | On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, the default settings for the router speed test contain links to d... |
| CVE-2020-28093 | HIGH | 7.2 | 1.2% | Dec 28, 2020 | On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now