2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-36209HIGH7An issue was discovered in the late-static crate before 0.4.0 for Rust. Because Sync is implemented for LateStatic with ...
CVE-2020-36208HIGH7.8An issue was discovered in the conquer-once crate before 0.3.2 for Rust. Thread crossing can occur for a non-Send but Sy...
CVE-2020-36207HIGH7An issue was discovered in the aovec crate through 2020-12-10 for Rust. Because Aovec<T> does not have bounds on its Sen...
CVE-2020-36206HIGH7An issue was discovered in the rusb crate before 0.7.0 for Rust. Because of a lack of Send and Sync bounds, a data race ...
CVE-2020-36201HIGH7.5An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655,...
CVE-2020-35845HIGH7.8FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0x96cf.
CVE-2020-35844HIGH7.8FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0xbe9c4.
CVE-2020-35576HIGH8.8A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216...
CVE-2020-35239HIGH8.8A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method ove...
CVE-2020-29001HIGH7.2An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6...
CVE-2020-29000HIGH7.2An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the RTSP service that allow...
CVE-2020-28999HIGH7.2An issue was discovered in Apexis Streaming Video Web Application on Geeni GNC-CW013 doorbell 1.8.1 devices. A remote at...
CVE-2020-28874HIGH7.5reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business...
CVE-2020-27814HIGH7.8A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw ...
CVE-2020-27541HIGH7.5Denial of Service vulnerability in Rostelecom CS-C2SHW 5.0.082.1. AgentGreen service has a bug in parsing broadcast disc...
CVE-2020-27288HIGH7.8An untrusted pointer dereference has been identified in the way TPEditor(v1.98 and prior) processes project files, allow...
CVE-2020-27284HIGH7.8TPEditor (v1.98 and prior) is vulnerable to two out-of-bounds write instances in the way it processes project files, all...
CVE-2020-27280HIGH7.8A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an atta...
CVE-2020-25737HIGH7.8An elevation of privilege vulnerability exists in Hackolade versions prior 4.2.0 on Windows has an issue in specific dep...
CVE-2020-25173HIGH7.8An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reol...
CVE-2020-25169HIGH7.5The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink serv...
CVE-2020-24549HIGH8.8openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server.
CVE-2020-23826HIGH8.8The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection vi...
CVE-2020-23449HIGH7.5newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexCon...
CVE-2020-23162HIGH7.5Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows re...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now