2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-25112CRITICAL9.8An issue was discovered in the IPv6 stack in Contiki through 3.0. There are inconsistent checks for IPv6 header extensio...
CVE-2020-25111CRITICAL9.8An issue was discovered in the IPv6 stack in Contiki through 3.0. There is an insufficient check for the IPv6 header len...
CVE-2020-25110CRITICAL9.8An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The length byte of a domain name in a DNS q...
CVE-2020-25109CRITICAL9.8An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The number of DNS queries/responses (set in...
CVE-2020-25108CRITICAL9.8An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The DNS response data length is not checked...
CVE-2020-25107CRITICAL9.8An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. There is no check on whether a domain name ...
CVE-2020-24383CRITICAL9.1An issue was discovered in FNET through 4.6.4. The code for processing resource records in mDNS queries doesn't check fo...
CVE-2020-24341CRITICAL9.1An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The TCP input data processing function in pico_tcp.c do...
CVE-2020-24338CRITICAL9.8An issue was discovered in picoTCP through 1.7.0. The DNS domain name record decompression functionality in pico_dns_dec...
CVE-2020-24336CRITICAL9.8An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answe...
CVE-2020-17467CRITICAL9.1An issue was discovered in FNET through 4.6.4. The code for processing the hostname from an LLMNR request doesn't check ...
CVE-2020-17441CRITICAL9.1An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 headers does not validate whether the IPv6 pa...
CVE-2020-17438CRITICAL9.8An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented pack...
CVE-2020-27730CRITICAL9.8In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling sys...
CVE-2020-5948CRITICAL9.6On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6....
CVE-2020-19165CRITICAL9.8PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.
CVE-2020-29574CRITICAL9.8An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to exe...
CVE-2020-28440CRITICAL9.8All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.
CVE-2020-28439CRITICAL9.8This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depe...
CVE-2020-27134CRITICAL9.9Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a...
CVE-2020-27133CRITICAL9.9Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a...
CVE-2020-27132CRITICAL9.9Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a...
CVE-2020-27127CRITICAL9.9Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a...
CVE-2020-15357CRITICAL9.8Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to exec...
CVE-2020-29591CRITICAL9.8Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deploy...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now