2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-21932 | MEDIUM | 5.3 | 1.3% | Jul 21, 2021 | A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass logi... |
| CVE-2020-20262 | MEDIUM | 6.5 | 2.1% | Jul 21, 2021 | Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/no... |
| CVE-2020-20221 | MEDIUM | 6.5 | 2.9% | Jul 21, 2021 | Mikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the ... |
| CVE-2020-20219 | MEDIUM | 6.5 | 2.0% | Jul 21, 2021 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy pro... |
| CVE-2020-19609 | MEDIUM | 5.5 | 1.0% | Jul 21, 2021 | Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF file... |
| CVE-2020-25205 | MEDIUM | 6.1 | 0.9% | Jul 20, 2021 | The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 is vulnerable to stored XSS in the set_banner() fun... |
| CVE-2020-36431 | MEDIUM | 5.5 | 0.3% | Jul 20, 2021 | Unicorn Engine 1.0.2 has an out-of-bounds write in helper_wfe_arm. |
| CVE-2020-36429 | MEDIUM | 5.5 | 0.3% | Jul 20, 2021 | Variant_encodeJson in open62541 1.x before 1.0.4 has an out-of-bounds write for a large recursion depth. |
| CVE-2020-29503 | MEDIUM | 4.4 | 0.2% | Jul 19, 2021 | Dell EMC PowerStore versions prior to 1.0.3.0.5.xxx contain a file permission Vulnerability. A locally authenticated att... |
| CVE-2020-29499 | MEDIUM | 6.7 | 0.4% | Jul 19, 2021 | Dell EMC PowerStore versions prior to 1.0.3.0.5.006 contain an OS Command Injection vulnerability in PowerStore X enviro... |
| CVE-2020-20249 | MEDIUM | 6.5 | 1.8% | Jul 19, 2021 | Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending ... |
| CVE-2020-20248 | MEDIUM | 6.5 | 1.8% | Jul 19, 2021 | Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authen... |
| CVE-2020-36427 | MEDIUM | 5.5 | 0.7% | Jul 19, 2021 | GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image. |
| CVE-2020-36425 | MEDIUM | 5.3 | 0.9% | Jul 19, 2021 | An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether ... |
| CVE-2020-36424 | MEDIUM | 4.7 | 0.3% | Jul 19, 2021 | An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-H... |
| CVE-2020-36422 | MEDIUM | 5.3 | 1.3% | Jul 19, 2021 | An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to ... |
| CVE-2020-36421 | MEDIUM | 5.3 | 1.6% | Jul 19, 2021 | An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA priva... |
| CVE-2020-20230 | MEDIUM | 6.5 | 1.9% | Jul 19, 2021 | Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authentic... |
| CVE-2020-5031 | MEDIUM | 5.4 | 0.5% | Jul 19, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2020-4980 | MEDIUM | 6.5 | 0.3% | Jul 16, 2021 | IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host conn... |
| CVE-2020-4675 | MEDIUM | 6.5 | 0.5% | Jul 16, 2021 | IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attac... |
| CVE-2020-23707 | MEDIUM | 6.5 | 1.1% | Jul 15, 2021 | A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_progressive() at ok_jpg.c:1054 of ok-file... |
| CVE-2020-23706 | MEDIUM | 6.5 | 1.0% | Jul 15, 2021 | A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() ok_jpg.c:1102 of ok-fil... |
| CVE-2020-23705 | MEDIUM | 6.5 | 1.0% | Jul 15, 2021 | A global buffer overflow vulnerability in jfif_encode at jfif.c:701 of ffjpeg through 2020-06-22 allows attackers to cau... |
| CVE-2020-12732 | MEDIUM | 6.5 | 0.9% | Jul 15, 2021 | DEPSTECH WiFi Digital Microscope 3 has a default SSID of Jetion_xxxxxxxx with a password of 12345678. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now