2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35742 | HIGH | 7.6 | 0.6% | Dec 31, 2020 | HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL para... |
| CVE-2020-25850 | HIGH | 7.5 | 1.1% | Dec 31, 2020 | The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can us... |
| CVE-2020-25846 | HIGH | 7.4 | 1.0% | Dec 31, 2020 | The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB... |
| CVE-2020-25845 | HIGH | 7.4 | 1.0% | Dec 31, 2020 | Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being re... |
| CVE-2020-25842 | HIGH | 7.5 | 0.5% | Dec 31, 2020 | The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access a... |
| CVE-2020-19664 | HIGH | 8.8 | 5.3% | Dec 31, 2020 | DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.... |
| CVE-2020-13654 | HIGH | 7.5 | 1.9% | Dec 31, 2020 | XWiki Platform before 12.8 mishandles escaping in the property displayer. |
| CVE-2020-26296 | HIGH | 8.7 | 1.4% | Dec 30, 2020 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design... |
| CVE-2020-28095 | HIGH | 7.5 | 1.2% | Dec 30, 2020 | On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will tr... |
| CVE-2020-35737 | HIGH | 7.5 | 10.3% | Dec 30, 2020 | In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information... |
| CVE-2020-35849 | HIGH | 7.5 | 1.6% | Dec 30, 2020 | An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unp... |
| CVE-2020-29228 | HIGH | 7.5 | 1.2% | Dec 30, 2020 | EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Pag... |
| CVE-2020-28736 | HIGH | 8.8 | 1.1% | Dec 30, 2020 | Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.M... |
| CVE-2020-28735 | HIGH | 8.8 | 1.1% | Dec 30, 2020 | Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role). |
| CVE-2020-28734 | HIGH | 8.8 | 1.1% | Dec 30, 2020 | Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role. |
| CVE-2020-27848 | HIGH | 8.8 | 1.2% | Dec 30, 2020 | dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOr... |
| CVE-2020-35841 | HIGH | 7.6 | 0.6% | Dec 30, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v... |
| CVE-2020-35839 | HIGH | 8.1 | 0.7% | Dec 30, 2020 | Certain NETGEAR devices are affected by Stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
| CVE-2020-35831 | HIGH | 8.1 | 0.9% | Dec 30, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
| CVE-2020-35802 | HIGH | 7.5 | 1.1% | Dec 30, 2020 | Certain NETGEAR devices are affected by disclosure of sensitive information. This affects CBR40 before 2.5.0.14, RBW30 b... |
| CVE-2020-35801 | HIGH | 7.3 | 1.7% | Dec 30, 2020 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects JGS516PE before 2.6.0... |
| CVE-2020-35798 | HIGH | 7.8 | 0.8% | Dec 30, 2020 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.... |
| CVE-2020-35789 | HIGH | 8.8 | 2.7% | Dec 30, 2020 | NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user. |
| CVE-2020-35787 | HIGH | 8 | 0.5% | Dec 30, 2020 | Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D3600 before 1.0.0.76, ... |
| CVE-2020-35785 | HIGH | 8.8 | 0.7% | Dec 30, 2020 | NETGEAR DGN2200v1 devices before v1.0.0.60 mishandle HTTPd authentication (aka PSV-2020-0363, PSV-2020-0364, and PSV-202... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now