2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-28194CRITICAL9.8Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length fie...
CVE-2020-26547CRITICAL9.8Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows...
CVE-2020-15836CRITICAL9.8An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function passes untrusted...
CVE-2020-15835CRITICAL9.8An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocum...
CVE-2020-15833CRITICAL9.8An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The Dropbear SSH daemon has been modified to...
CVE-2020-13859CRITICAL9.8An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with ...
CVE-2020-13858CRITICAL9.8An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented ...
CVE-2020-15690CRITICAL9.8In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline characte...
CVE-2020-15568CRITICAL9.8TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic cla...
CVE-2020-29557CRITICAL9.8An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web inter...
CVE-2020-35547CRITICAL9.1A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to ga...
CVE-2020-4682CRITICAL9.8IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, ca...
CVE-2020-35124CRITICAL9.6A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inj...
CVE-2020-25785CRITICAL9.8An issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15....
CVE-2020-25784CRITICAL9.8An issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15....
CVE-2020-25783CRITICAL9.8An issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15....
CVE-2020-25782CRITICAL9.8An issue was discovered on Accfly Wireless Security IR Camera 720P System with software versions v3.10.73 through v4.15....
CVE-2020-23361CRITICAL9.8phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishand...
CVE-2020-23360CRITICAL9.8oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical passwor...
CVE-2020-23359CRITICAL9.8WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparis...
CVE-2020-27299CRITICAL9.1The affected product is vulnerable to an out-of-bounds read, which may allow an attacker to obtain and disclose sensitiv...
CVE-2020-27297CRITICAL9.8The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory wit...
CVE-2020-6779CRITICAL10Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including ver...
CVE-2020-36199CRITICAL9.8TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input par...
CVE-2020-35270CRITICAL9.1Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now