2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-17438 | CRITICAL | 9.8 | 18.5% | Dec 11, 2020 | An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented pack... |
| CVE-2020-17437 | HIGH | 8.2 | 2.8% | Dec 11, 2020 | An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP pack... |
| CVE-2020-13988 | HIGH | 7.5 | 3.9% | Dec 11, 2020 | An issue was discovered in Contiki through 3.0. An Integer Overflow exists in the uIP TCP/IP Stack component when parsin... |
| CVE-2020-13987 | HIGH | 7.5 | 3.2% | Dec 11, 2020 | An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack compo... |
| CVE-2020-13986 | HIGH | 7.5 | 3.0% | Dec 11, 2020 | An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when handling ... |
| CVE-2020-13985 | HIGH | 7.5 | 4.8% | Dec 11, 2020 | An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack compone... |
| CVE-2020-13984 | HIGH | 7.5 | 1.7% | Dec 11, 2020 | An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when processin... |
| CVE-2020-15376 | MEDIUM | 4.3 | 0.9% | Dec 11, 2020 | Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness ... |
| CVE-2020-15375 | MEDIUM | 6.7 | 0.3% | Dec 11, 2020 | Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input vali... |
| CVE-2020-29455 | MEDIUM | 6.1 | 1.1% | Dec 11, 2020 | A cross-Site Scripting (XSS) vulnerability in this.showInvalid and this.showInvalidCountry in SmartyStreets liveAddressP... |
| CVE-2020-27730 | CRITICAL | 9.8 | 1.7% | Dec 11, 2020 | In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling sys... |
| CVE-2020-5950 | MEDIUM | 5.3 | 1.0% | Dec 11, 2020 | On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to ... |
| CVE-2020-5949 | HIGH | 7.5 | 1.0% | Dec 11, 2020 | On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with a... |
| CVE-2020-5948 | CRITICAL | 9.6 | 1.0% | Dec 11, 2020 | On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.... |
| CVE-2020-35149 | MEDIUM | 5.3 | 1.0% | Dec 11, 2020 | lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., __proto__) can be copied... |
| CVE-2020-27825 | MEDIUM | 5.7 | 0.3% | Dec 11, 2020 | A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race proble... |
| CVE-2020-27713 | HIGH | 7.5 | 1.3% | Dec 11, 2020 | In certain configurations on version 13.1.3.4, when a BIG-IP AFM HTTP security profile is applied to a virtual server an... |
| CVE-2020-26421 | MEDIUM | 5.3 | 2.6% | Dec 11, 2020 | Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of... |
| CVE-2020-26420 | MEDIUM | 5.3 | 2.6% | Dec 11, 2020 | Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injecti... |
| CVE-2020-26419 | MEDIUM | 5.3 | 2.8% | Dec 11, 2020 | Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture... |
| CVE-2020-26418 | MEDIUM | 5.3 | 3.0% | Dec 11, 2020 | Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet inject... |
| CVE-2020-19165 | CRITICAL | 9.8 | 1.6% | Dec 11, 2020 | PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter. |
| CVE-2020-7791 | HIGH | 7.5 | 3.0% | Dec 11, 2020 | This affects the package i18n before 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tag... |
| CVE-2020-29574 | CRITICAL | 9.8 | 4.7% | Dec 11, 2020 | An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to exe... |
| CVE-2020-28440 | CRITICAL | 9.8 | 2.0% | Dec 11, 2020 | All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now