2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26907HIGH8.8Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2...
CVE-2020-26906HIGH8.8Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB...
CVE-2020-26905HIGH8.8Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB...
CVE-2020-26904HIGH8.8Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB...
CVE-2020-26903HIGH8.8Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB...
CVE-2020-26902HIGH8.8Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2...
CVE-2020-26901MEDIUM6.5Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK752 before 3.2.15.25, RBR75...
CVE-2020-26900HIGH8.8Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB...
CVE-2020-26899MEDIUM6.5Certain NETGEAR devices are affected by disclosure of sensitive information. This affects CBR40 before 2.5.0.10, RBK752 ...
CVE-2020-26898HIGH8.8NETGEAR RAX40 devices before 1.0.3.80 are affected by incorrect configuration of security settings.
CVE-2020-26897HIGH8.8Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RB...
CVE-2020-26522HIGH8.8A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows...
CVE-2020-26162MEDIUM6.1Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description p...
CVE-2020-15838HIGH8.8The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder h...
CVE-2020-13626MEDIUM4.6OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authori...
CVE-2020-15243CRITICAL9.8Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore sh...
CVE-2020-26894HIGH7.8LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in th...
CVE-2020-15241MEDIUM6.1TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vul...
CVE-2020-15242MEDIUM6.1Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the t...
CVE-2020-1914CRITICAL9.8A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df62082462...
CVE-2020-9048HIGH8.1A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could a...
CVE-2020-26802HIGH8.8forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=s...
CVE-2020-10816HIGH7.5Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed ser...
CVE-2020-5389MEDIUM6.5Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain...
CVE-2020-4799HIGH7.8IBM Informix spatial 14.10 could allow a local user to execute commands as a privileged user due to an out of bounds wri...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now