2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-21932MEDIUM5.3A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass logi...
CVE-2020-20262MEDIUM6.5Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/no...
CVE-2020-20221MEDIUM6.5Mikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the ...
CVE-2020-20219MEDIUM6.5Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy pro...
CVE-2020-19609MEDIUM5.5Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF file...
CVE-2020-25205MEDIUM6.1The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 is vulnerable to stored XSS in the set_banner() fun...
CVE-2020-36431MEDIUM5.5Unicorn Engine 1.0.2 has an out-of-bounds write in helper_wfe_arm.
CVE-2020-36429MEDIUM5.5Variant_encodeJson in open62541 1.x before 1.0.4 has an out-of-bounds write for a large recursion depth.
CVE-2020-29503MEDIUM4.4Dell EMC PowerStore versions prior to 1.0.3.0.5.xxx contain a file permission Vulnerability. A locally authenticated att...
CVE-2020-29499MEDIUM6.7Dell EMC PowerStore versions prior to 1.0.3.0.5.006 contain an OS Command Injection vulnerability in PowerStore X enviro...
CVE-2020-20249MEDIUM6.5Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending ...
CVE-2020-20248MEDIUM6.5Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authen...
CVE-2020-36427MEDIUM5.5GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image.
CVE-2020-36425MEDIUM5.3An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether ...
CVE-2020-36424MEDIUM4.7An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-H...
CVE-2020-36422MEDIUM5.3An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to ...
CVE-2020-36421MEDIUM5.3An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA priva...
CVE-2020-20230MEDIUM6.5Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authentic...
CVE-2020-5031MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2020-4980MEDIUM6.5IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host conn...
CVE-2020-4675MEDIUM6.5IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attac...
CVE-2020-23707MEDIUM6.5A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_progressive() at ok_jpg.c:1054 of ok-file...
CVE-2020-23706MEDIUM6.5A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() ok_jpg.c:1102 of ok-fil...
CVE-2020-23705MEDIUM6.5A global buffer overflow vulnerability in jfif_encode at jfif.c:701 of ffjpeg through 2020-06-22 allows attackers to cau...
CVE-2020-12732MEDIUM6.5DEPSTECH WiFi Digital Microscope 3 has a default SSID of Jetion_xxxxxxxx with a password of 12345678.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now