2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-27720HIGH7.5On BIG-IP LTM/CGNAT version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when processing NAT66 ...
CVE-2020-27719MEDIUM6.1On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an u...
CVE-2020-27717HIGH7.5On BIG-IP DNS 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, undisclosed series ...
CVE-2020-27716HIGH7.5On versions 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when a BIG-IP APM vir...
CVE-2020-27715HIGH7.5On BIG-IP 15.1.0-15.1.0.5 and 14.1.0-14.1.3, crafted TLS request to the BIG-IP management interface via port 443 can cau...
CVE-2020-27714HIGH7.5On the BIG-IP AFM version 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when a Protocol Inspection Profile is att...
CVE-2020-29189HIGH8.1Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read...
CVE-2020-28190MEDIUM5.9TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP...
CVE-2020-28189Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-29189. Reason: This candidate is a reservation d...
CVE-2020-28188CRITICAL9.8Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inje...
CVE-2020-28187CRITICAL9.8Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, ...
CVE-2020-28186HIGH7.3Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functi...
CVE-2020-28185MEDIUM5.3User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid us...
CVE-2020-28184MEDIUM5.4Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitr...
CVE-2020-28169HIGH7The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory ...
CVE-2020-27725MEDIUM4.3In version 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 of BIG-IP DNS, GTM, and...
CVE-2020-27724MEDIUM6.5In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5....
CVE-2020-27721HIGH7.5In versions 16.0.0-16.0.0.1, 15.1.0-15.1.1, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, in a B...
CVE-2020-27718HIGH7.5When a BIG-IP ASM or Advanced WAF system running version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3....
CVE-2020-35677MEDIUM4.8BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator...
CVE-2020-35676MEDIUM6.1BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the se...
CVE-2020-35669MEDIUM6.1An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the ap...
CVE-2020-5684MEDIUM4.8iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not veri...
CVE-2020-5681HIGH7.8Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlie...
CVE-2020-2505LOW2.3If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. Q...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now