2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-17438CRITICAL9.8An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented pack...
CVE-2020-17437HIGH8.2An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP pack...
CVE-2020-13988HIGH7.5An issue was discovered in Contiki through 3.0. An Integer Overflow exists in the uIP TCP/IP Stack component when parsin...
CVE-2020-13987HIGH7.5An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack compo...
CVE-2020-13986HIGH7.5An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when handling ...
CVE-2020-13985HIGH7.5An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack compone...
CVE-2020-13984HIGH7.5An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when processin...
CVE-2020-15376MEDIUM4.3Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness ...
CVE-2020-15375MEDIUM6.7Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input vali...
CVE-2020-29455MEDIUM6.1A cross-Site Scripting (XSS) vulnerability in this.showInvalid and this.showInvalidCountry in SmartyStreets liveAddressP...
CVE-2020-27730CRITICAL9.8In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling sys...
CVE-2020-5950MEDIUM5.3On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to ...
CVE-2020-5949HIGH7.5On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with a...
CVE-2020-5948CRITICAL9.6On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6....
CVE-2020-35149MEDIUM5.3lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., __proto__) can be copied...
CVE-2020-27825MEDIUM5.7A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race proble...
CVE-2020-27713HIGH7.5In certain configurations on version 13.1.3.4, when a BIG-IP AFM HTTP security profile is applied to a virtual server an...
CVE-2020-26421MEDIUM5.3Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of...
CVE-2020-26420MEDIUM5.3Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injecti...
CVE-2020-26419MEDIUM5.3Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture...
CVE-2020-26418MEDIUM5.3Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet inject...
CVE-2020-19165CRITICAL9.8PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.
CVE-2020-7791HIGH7.5This affects the package i18n before 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tag...
CVE-2020-29574CRITICAL9.8An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to exe...
CVE-2020-28440CRITICAL9.8All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now