2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-23586MEDIUM4.3A vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unau...
CVE-2020-23584CRITICAL9.8Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes ar...
CVE-2020-23593MEDIUM6.5A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthentic...
CVE-2020-23585HIGH8.8A remote attacker can conduct a cross-site request forgery (CSRF) attack on OPTILINK OP-XT71000N Hardware Version: V2.2 ...
CVE-2020-23583CRITICAL9.8OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary ...
CVE-2020-23582MEDIUM6.5A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, r...
CVE-2020-12508HIGH7.5In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path trave...
CVE-2020-12507HIGH8.8In s::can moni::tools before version 4.2 an authenticated attacker could get full access to the database through SQL inj...
CVE-2020-12931HIGH7.8Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their p...
CVE-2020-12930HIGH7.8Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their priv...
CVE-2020-35473MEDIUM4.3An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifica...
CVE-2020-12509HIGH7.5In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path trave...
CVE-2020-22820CRITICAL9.8MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.
CVE-2020-22819CRITICAL9.8MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.
CVE-2020-22818CRITICAL9.8MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.
CVE-2020-36608MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this iss...
CVE-2020-4099HIGH7.5The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forge...
CVE-2020-36605MEDIUM4.4Incorrect Default Permissions vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe compon...
CVE-2020-23255Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-21016CRITICAL9.8D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/S...
CVE-2020-5355MEDIUM4.3The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and ...
CVE-2020-9285MEDIUM6.8Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware...
CVE-2020-12744HIGH7.8The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during ...
CVE-2020-23648HIGH7.5Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an...
CVE-2020-15853MEDIUM5.3supybot-fedora implements the command 'refresh', that refreshes the cache of all users from FAS. This takes quite a whil...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now