2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26582HIGH8.8D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metachara...
CVE-2020-7741CRITICAL9.9This affects the package hellojs before 1.18.6. The code get the param oauth_redirect from url and pass it to location.a...
CVE-2020-7739HIGH8.2This affects all versions of package phantomjs-seo. It is possible for an attacker to craft a url that will be passed to...
CVE-2020-26575HIGH7.5In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was add...
CVE-2020-26574CRITICAL9.6Leostream Connection Broker 8.2.x is affected by stored XSS. An unauthenticated attacker can inject arbitrary JavaScript...
CVE-2020-25866HIGH7.5In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a bu...
CVE-2020-25863HIGH7.5In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was ad...
CVE-2020-25862HIGH7.5In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in ...
CVE-2020-25803HIGH7.2Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat...
CVE-2020-25743LOW3.2hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_...
CVE-2020-25742LOW3.2pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not...
CVE-2020-8782CRITICAL9.8Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.
CVE-2020-8781HIGH7.8Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-pri...
CVE-2020-7466HIGH7.5The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication m...
CVE-2020-7465CRITICAL9.8The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet...
CVE-2020-25802HIGH7.2Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat...
CVE-2020-25644HIGH7.5A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It m...
CVE-2020-25643HIGH7.2A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read ove...
CVE-2020-25641MEDIUM5.5A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec reques...
CVE-2020-25637MEDIUM6.7A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting i...
CVE-2020-24219HIGH7.5An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthentic...
CVE-2020-24218CRITICAL9.8An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the p...
CVE-2020-24217CRITICAL9.8An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpo...
CVE-2020-24216HIGH7.5An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrato...
CVE-2020-15598HIGH7.5Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Tr...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now