2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26907 | HIGH | 8.8 | 1.5% | Oct 9, 2020 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2... |
| CVE-2020-26906 | HIGH | 8.8 | 0.6% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB... |
| CVE-2020-26905 | HIGH | 8.8 | 0.8% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB... |
| CVE-2020-26904 | HIGH | 8.8 | 0.7% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB... |
| CVE-2020-26903 | HIGH | 8.8 | 0.5% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB... |
| CVE-2020-26902 | HIGH | 8.8 | 2.2% | Oct 9, 2020 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2... |
| CVE-2020-26901 | MEDIUM | 6.5 | 0.5% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK752 before 3.2.15.25, RBR75... |
| CVE-2020-26900 | HIGH | 8.8 | 0.5% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB... |
| CVE-2020-26899 | MEDIUM | 6.5 | 0.8% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of sensitive information. This affects CBR40 before 2.5.0.10, RBK752 ... |
| CVE-2020-26898 | HIGH | 8.8 | 0.6% | Oct 9, 2020 | NETGEAR RAX40 devices before 1.0.3.80 are affected by incorrect configuration of security settings. |
| CVE-2020-26897 | HIGH | 8.8 | 0.6% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB... |
| CVE-2020-26522 | HIGH | 8.8 | 0.8% | Oct 9, 2020 | A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows... |
| CVE-2020-26162 | MEDIUM | 6.1 | 0.6% | Oct 9, 2020 | Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description p... |
| CVE-2020-15838 | HIGH | 8.8 | 1.2% | Oct 9, 2020 | The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder h... |
| CVE-2020-13626 | MEDIUM | 4.6 | 0.3% | Oct 9, 2020 | OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authori... |
| CVE-2020-15243 | CRITICAL | 9.8 | 1.2% | Oct 8, 2020 | Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore sh... |
| CVE-2020-26894 | HIGH | 7.8 | 0.4% | Oct 8, 2020 | LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in th... |
| CVE-2020-15241 | MEDIUM | 6.1 | 1.0% | Oct 8, 2020 | TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vul... |
| CVE-2020-15242 | MEDIUM | 6.1 | 0.8% | Oct 8, 2020 | Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the t... |
| CVE-2020-1914 | CRITICAL | 9.8 | 2.4% | Oct 8, 2020 | A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df62082462... |
| CVE-2020-9048 | HIGH | 8.1 | 1.1% | Oct 8, 2020 | A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could a... |
| CVE-2020-26802 | HIGH | 8.8 | 0.6% | Oct 8, 2020 | forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=s... |
| CVE-2020-10816 | HIGH | 7.5 | 4.8% | Oct 8, 2020 | Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed ser... |
| CVE-2020-5389 | MEDIUM | 6.5 | 0.9% | Oct 8, 2020 | Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain... |
| CVE-2020-4799 | HIGH | 7.8 | 0.4% | Oct 8, 2020 | IBM Informix spatial 14.10 could allow a local user to execute commands as a privileged user due to an out of bounds wri... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now