2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11910 | MEDIUM | 5.3 | 10.8% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read. |
| CVE-2020-11909 | MEDIUM | 5.3 | 3.6% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow. |
| CVE-2020-11908 | MEDIUM | 4.3 | 1.9% | Jun 17, 2020 | The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP. |
| CVE-2020-11907 | MEDIUM | 6.3 | 2.0% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 improperly handles a Length Parameter Inconsistency in TCP. |
| CVE-2020-11906 | MEDIUM | 6.3 | 2.0% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow. |
| CVE-2020-11905 | MEDIUM | 6.5 | 2.1% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read. |
| CVE-2020-11904 | HIGH | 7.3 | 3.2% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Wri... |
| CVE-2020-11903 | MEDIUM | 6.5 | 2.1% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.28 has a DHCP Out-of-bounds Read. |
| CVE-2020-11902 | HIGH | 7.3 | 9.3% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read. |
| CVE-2020-11901 | CRITICAL | 9 | 21.1% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response. |
| CVE-2020-11900 | HIGH | 8.2 | 12.8% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free. |
| CVE-2020-11899 | MEDIUM | 5.4 | 18.4% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. |
| CVE-2020-11898 | CRITICAL | 9.1 | 18.7% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might all... |
| CVE-2020-11897 | CRITICAL | 10 | 9.1% | Jun 17, 2020 | The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets. |
| CVE-2020-11896 | CRITICAL | 10 | 37.0% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling. |
| CVE-2020-14214 | MEDIUM | 6.5 | 0.7% | Jun 16, 2020 | Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decis... |
| CVE-2020-14213 | MEDIUM | 5.4 | 0.6% | Jun 16, 2020 | In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data... |
| CVE-2020-4054 | HIGH | 7.3 | 1.9% | Jun 16, 2020 | In Sanitize (RubyGem sanitize) greater than or equal to 3.0.0 and less than 5.2.1, there is a cross-site scripting vulne... |
| CVE-2020-4053 | MEDIUM | 6.8 | 1.5% | Jun 16, 2020 | In Helm greater than or equal to 3.0.0 and less than 3.2.4, a path traversal attack is possible when installing Helm plu... |
| CVE-2020-4052 | MEDIUM | 6.1 | 0.8% | Jun 16, 2020 | In Wiki.js before 2.4.107, there is a stored cross-site scripting through template injection. This vulnerability exists ... |
| CVE-2020-14212 | HIGH | 8.8 | 1.7% | Jun 16, 2020 | FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavformat/aviobuf.c because dnn_backend_native.... |
| CVE-2020-14210 | MEDIUM | 6.1 | 1.0% | Jun 16, 2020 | Reflected Cross-Site Scripting (XSS) vulnerability in MONITORAPP WAF in which script can be executed when responding to ... |
| CVE-2020-9289 | HIGH | 7.5 | 2.2% | Jun 16, 2020 | Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, For... |
| CVE-2020-7513 | HIGH | 7.5 | 0.8% | Jun 16, 2020 | A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy T300 (Firmware version 1.5.2 and o... |
| CVE-2020-7512 | CRITICAL | 9.8 | 1.4% | Jun 16, 2020 | A CWE-1103: Use of Platform-Dependent Third Party Components with vulnerabilities vulnerability exists in Easergy T300 (... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now