2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-35742HIGH7.6HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL para...
CVE-2020-25850HIGH7.5The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can us...
CVE-2020-25846HIGH7.4The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB...
CVE-2020-25845HIGH7.4Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being re...
CVE-2020-25842HIGH7.5The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access a...
CVE-2020-19664HIGH8.8DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction....
CVE-2020-13654HIGH7.5XWiki Platform before 12.8 mishandles escaping in the property displayer.
CVE-2020-26296HIGH8.7Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design...
CVE-2020-28095HIGH7.5On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will tr...
CVE-2020-35737HIGH7.5In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information...
CVE-2020-35849HIGH7.5An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unp...
CVE-2020-29228HIGH7.5EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Pag...
CVE-2020-28736HIGH8.8Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.M...
CVE-2020-28735HIGH8.8Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
CVE-2020-28734HIGH8.8Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
CVE-2020-27848HIGH8.8dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOr...
CVE-2020-35841HIGH7.6Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v...
CVE-2020-35839HIGH8.1Certain NETGEAR devices are affected by Stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b...
CVE-2020-35831HIGH8.1Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b...
CVE-2020-35802HIGH7.5Certain NETGEAR devices are affected by disclosure of sensitive information. This affects CBR40 before 2.5.0.14, RBW30 b...
CVE-2020-35801HIGH7.3Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects JGS516PE before 2.6.0...
CVE-2020-35798HIGH7.8Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1....
CVE-2020-35789HIGH8.8NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.
CVE-2020-35787HIGH8Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D3600 before 1.0.0.76, ...
CVE-2020-35785HIGH8.8NETGEAR DGN2200v1 devices before v1.0.0.60 mishandle HTTPd authentication (aka PSV-2020-0363, PSV-2020-0364, and PSV-202...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now