2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-35926CRITICAL9.8An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha)...
CVE-2020-35902CRITICAL9.8An issue was discovered in the actix-codec crate before 0.3.0-beta.1 for Rust. There is a use-after-free in Framed.
CVE-2020-35898CRITICAL9.1An issue was discovered in the actix-utils crate before 2.0.0 for Rust. The Cell implementation allows obtaining more th...
CVE-2020-35851CRITICAL9.8HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command...
CVE-2020-25848CRITICAL9.8HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password gener...
CVE-2020-25844CRITICAL9.8The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a sta...
CVE-2020-25843CRITICAL9.8NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole...
CVE-2020-17363CRITICAL9.9USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or n...
CVE-2020-12658CRITICAL9.8gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c...
CVE-2020-11103CRITICAL9.8JsLink in Webswing before 2.6.12 LTS, and 2.7.x and 20.x before 20.1, allows remote code execution.
CVE-2020-35173CRITICAL9.8The Amaze File Manager application before 3.4.2 for Android does not properly restrict intents for controlling the FTP s...
CVE-2020-29594CRITICAL9.8Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3...
CVE-2020-35848CRITICAL9.8Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
CVE-2020-35847CRITICAL9.8Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
CVE-2020-35846CRITICAL9.8Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
CVE-2020-35800CRITICAL9.4Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects AC2100 before 1.2.0.7...
CVE-2020-35799CRITICAL9.8Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600...
CVE-2020-35797CRITICAL9.8NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an unauthenticated attacker.
CVE-2020-35796CRITICAL9.8Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects CBR40 before 2.5....
CVE-2020-35795CRITICAL9.8Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects AC2100 before 1.2...
CVE-2020-10208CRITICAL9.9Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, A...
CVE-2020-10210CRITICAL9.8Because of hard-coded SSH keys for the root user in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6...
CVE-2020-10207CRITICAL9.8Use of Hard-coded Credentials in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6...
CVE-2020-10148CRITICAL9.8The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API com...
CVE-2020-28283CRITICAL9.8Prototype pollution vulnerability in 'libnested' versions 0.0.0 through 1.5.0 allows an attacker to cause a denial of se...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now