2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36209 | HIGH | 7 | 0.4% | Jan 26, 2021 | An issue was discovered in the late-static crate before 0.4.0 for Rust. Because Sync is implemented for LateStatic with ... |
| CVE-2020-36208 | HIGH | 7.8 | 0.4% | Jan 26, 2021 | An issue was discovered in the conquer-once crate before 0.3.2 for Rust. Thread crossing can occur for a non-Send but Sy... |
| CVE-2020-36207 | HIGH | 7 | 0.3% | Jan 26, 2021 | An issue was discovered in the aovec crate through 2020-12-10 for Rust. Because Aovec<T> does not have bounds on its Sen... |
| CVE-2020-36206 | HIGH | 7 | 0.3% | Jan 26, 2021 | An issue was discovered in the rusb crate before 0.7.0 for Rust. Because of a lack of Send and Sync bounds, a data race ... |
| CVE-2020-36201 | HIGH | 7.5 | 0.8% | Jan 26, 2021 | An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655,... |
| CVE-2020-35845 | HIGH | 7.8 | 0.9% | Jan 26, 2021 | FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0x96cf. |
| CVE-2020-35844 | HIGH | 7.8 | 0.9% | Jan 26, 2021 | FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0xbe9c4. |
| CVE-2020-35576 | HIGH | 8.8 | 42.3% | Jan 26, 2021 | A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216... |
| CVE-2020-35239 | HIGH | 8.8 | 0.6% | Jan 26, 2021 | A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method ove... |
| CVE-2020-29001 | HIGH | 7.2 | 1.3% | Jan 26, 2021 | An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6... |
| CVE-2020-29000 | HIGH | 7.2 | 2.5% | Jan 26, 2021 | An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the RTSP service that allow... |
| CVE-2020-28999 | HIGH | 7.2 | 1.7% | Jan 26, 2021 | An issue was discovered in Apexis Streaming Video Web Application on Geeni GNC-CW013 doorbell 1.8.1 devices. A remote at... |
| CVE-2020-28874 | HIGH | 7.5 | 2.4% | Jan 26, 2021 | reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business... |
| CVE-2020-27814 | HIGH | 7.8 | 2.0% | Jan 26, 2021 | A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw ... |
| CVE-2020-27541 | HIGH | 7.5 | 1.1% | Jan 26, 2021 | Denial of Service vulnerability in Rostelecom CS-C2SHW 5.0.082.1. AgentGreen service has a bug in parsing broadcast disc... |
| CVE-2020-27288 | HIGH | 7.8 | 1.3% | Jan 26, 2021 | An untrusted pointer dereference has been identified in the way TPEditor(v1.98 and prior) processes project files, allow... |
| CVE-2020-27284 | HIGH | 7.8 | 1.2% | Jan 26, 2021 | TPEditor (v1.98 and prior) is vulnerable to two out-of-bounds write instances in the way it processes project files, all... |
| CVE-2020-27280 | HIGH | 7.8 | 1.3% | Jan 26, 2021 | A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an atta... |
| CVE-2020-25737 | HIGH | 7.8 | 0.3% | Jan 26, 2021 | An elevation of privilege vulnerability exists in Hackolade versions prior 4.2.0 on Windows has an issue in specific dep... |
| CVE-2020-25173 | HIGH | 7.8 | 0.3% | Jan 26, 2021 | An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reol... |
| CVE-2020-25169 | HIGH | 7.5 | 1.0% | Jan 26, 2021 | The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink serv... |
| CVE-2020-24549 | HIGH | 8.8 | 2.6% | Jan 26, 2021 | openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server. |
| CVE-2020-23826 | HIGH | 8.8 | 12.6% | Jan 26, 2021 | The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection vi... |
| CVE-2020-23449 | HIGH | 7.5 | 0.9% | Jan 26, 2021 | newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexCon... |
| CVE-2020-23162 | HIGH | 7.5 | 1.2% | Jan 26, 2021 | Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows re... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now