2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35926 | CRITICAL | 9.8 | 1.5% | Dec 31, 2020 | An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha)... |
| CVE-2020-35902 | CRITICAL | 9.8 | 1.6% | Dec 31, 2020 | An issue was discovered in the actix-codec crate before 0.3.0-beta.1 for Rust. There is a use-after-free in Framed. |
| CVE-2020-35898 | CRITICAL | 9.1 | 1.4% | Dec 31, 2020 | An issue was discovered in the actix-utils crate before 2.0.0 for Rust. The Cell implementation allows obtaining more th... |
| CVE-2020-35851 | CRITICAL | 9.8 | 1.7% | Dec 31, 2020 | HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command... |
| CVE-2020-25848 | CRITICAL | 9.8 | 1.7% | Dec 31, 2020 | HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password gener... |
| CVE-2020-25844 | CRITICAL | 9.8 | 1.9% | Dec 31, 2020 | The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a sta... |
| CVE-2020-25843 | CRITICAL | 9.8 | 1.9% | Dec 31, 2020 | NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole... |
| CVE-2020-17363 | CRITICAL | 9.9 | 4.4% | Dec 31, 2020 | USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or n... |
| CVE-2020-12658 | CRITICAL | 9.8 | 1.7% | Dec 31, 2020 | gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c... |
| CVE-2020-11103 | CRITICAL | 9.8 | 2.7% | Dec 30, 2020 | JsLink in Webswing before 2.6.12 LTS, and 2.7.x and 20.x before 20.1, allows remote code execution. |
| CVE-2020-35173 | CRITICAL | 9.8 | 1.7% | Dec 30, 2020 | The Amaze File Manager application before 3.4.2 for Android does not properly restrict intents for controlling the FTP s... |
| CVE-2020-29594 | CRITICAL | 9.8 | 1.6% | Dec 30, 2020 | Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3... |
| CVE-2020-35848 | CRITICAL | 9.8 | 75.0% | Dec 30, 2020 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function. |
| CVE-2020-35847 | CRITICAL | 9.8 | 98.3% | Dec 30, 2020 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function. |
| CVE-2020-35846 | CRITICAL | 9.8 | 93.2% | Dec 30, 2020 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function. |
| CVE-2020-35800 | CRITICAL | 9.4 | 1.9% | Dec 30, 2020 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects AC2100 before 1.2.0.7... |
| CVE-2020-35799 | CRITICAL | 9.8 | 1.2% | Dec 30, 2020 | Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600... |
| CVE-2020-35797 | CRITICAL | 9.8 | 2.1% | Dec 30, 2020 | NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an unauthenticated attacker. |
| CVE-2020-35796 | CRITICAL | 9.8 | 1.5% | Dec 30, 2020 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects CBR40 before 2.5.... |
| CVE-2020-35795 | CRITICAL | 9.8 | 1.2% | Dec 30, 2020 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects AC2100 before 1.2... |
| CVE-2020-10208 | CRITICAL | 9.9 | 4.1% | Dec 30, 2020 | Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, A... |
| CVE-2020-10210 | CRITICAL | 9.8 | 1.5% | Dec 29, 2020 | Because of hard-coded SSH keys for the root user in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6... |
| CVE-2020-10207 | CRITICAL | 9.8 | 2.5% | Dec 29, 2020 | Use of Hard-coded Credentials in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6... |
| CVE-2020-10148 | CRITICAL | 9.8 | 92.0% | Dec 29, 2020 | The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API com... |
| CVE-2020-28283 | CRITICAL | 9.8 | 3.2% | Dec 29, 2020 | Prototype pollution vulnerability in 'libnested' versions 0.0.0 through 1.5.0 allows an attacker to cause a denial of se... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now