2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5135 | CRITICAL | 9.8 | 26.9% | Oct 12, 2020 | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially exe... |
| CVE-2020-26948 | CRITICAL | 9.8 | 87.2% | Oct 10, 2020 | Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter. |
| CVE-2020-26935 | CRITICAL | 9.8 | 67.1% | Oct 10, 2020 | An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerabili... |
| CVE-2020-26928 | CRITICAL | 9.6 | 0.7% | Oct 9, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.... |
| CVE-2020-26927 | CRITICAL | 9.8 | 1.1% | Oct 9, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.7... |
| CVE-2020-26926 | CRITICAL | 9.6 | 0.5% | Oct 9, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.... |
| CVE-2020-26919 | CRITICAL | 9.8 | 57.2% | Oct 9, 2020 | NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level. |
| CVE-2020-26908 | CRITICAL | 9.8 | 2.0% | Oct 9, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.36, D7000 before 1.0.1.7... |
| CVE-2020-15243 | CRITICAL | 9.8 | 1.2% | Oct 8, 2020 | Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore sh... |
| CVE-2020-1914 | CRITICAL | 9.8 | 2.4% | Oct 8, 2020 | A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df62082462... |
| CVE-2020-25273 | CRITICAL | 9.8 | 1.8% | Oct 8, 2020 | In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php v... |
| CVE-2020-15175 | CRITICAL | 9.1 | 70.9% | Oct 7, 2020 | In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. The... |
| CVE-2020-11800 | CRITICAL | 9.8 | 9.2% | Oct 7, 2020 | Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code. |
| CVE-2020-13347 | CRITICAL | 9.1 | 2.3% | Oct 7, 2020 | A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the ... |
| CVE-2020-26607 | CRITICAL | 9.8 | 0.5% | Oct 6, 2020 | An issue was discovered in TimaService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. PendingInten... |
| CVE-2020-1907 | CRITICAL | 9.8 | 1.8% | Oct 6, 2020 | A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, Wha... |
| CVE-2020-7741 | CRITICAL | 9.9 | 1.5% | Oct 6, 2020 | This affects the package hellojs before 1.18.6. The code get the param oauth_redirect from url and pass it to location.a... |
| CVE-2020-26574 | CRITICAL | 9.6 | 2.1% | Oct 6, 2020 | Leostream Connection Broker 8.2.x is affected by stored XSS. An unauthenticated attacker can inject arbitrary JavaScript... |
| CVE-2020-8782 | CRITICAL | 9.8 | 1.8% | Oct 6, 2020 | Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution. |
| CVE-2020-7465 | CRITICAL | 9.8 | 2.8% | Oct 6, 2020 | The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet... |
| CVE-2020-24218 | CRITICAL | 9.8 | 1.9% | Oct 6, 2020 | An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the p... |
| CVE-2020-24217 | CRITICAL | 9.8 | 39.0% | Oct 6, 2020 | An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpo... |
| CVE-2020-24215 | CRITICAL | 9.8 | 19.0% | Oct 6, 2020 | An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use har... |
| CVE-2020-24214 | CRITICAL | 9.8 | 35.4% | Oct 6, 2020 | An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a ... |
| CVE-2020-16226 | CRITICAL | 9.8 | 2.2% | Oct 5, 2020 | Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, whic... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now