2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-35784HIGH7.2Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0...
CVE-2020-35782HIGH8.1Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0...
CVE-2020-35779HIGH8.6NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service.
CVE-2020-35778HIGH8.8Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36.
CVE-2020-35777HIGH8.4NETGEAR DGN2200v1 devices before v1.0.0.58 are affected by command injection.
CVE-2020-10209HIGH8.1Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx ser...
CVE-2020-27645HIGH8.8The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\...
CVE-2020-27644HIGH8.8The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\...
CVE-2020-16268HIGH8.8The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevate...
CVE-2020-9223HIGH7.5There is a denial of service vulnerability in some Huawei smartphones. Due to the improper processing of received abnorm...
CVE-2020-9207HIGH7.8There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not veri...
CVE-2020-9124HIGH7.5There is a memory leak vulnerability in some versions of Huawei CloudEngine product. An unauthenticated, remote attacker...
CVE-2020-9094HIGH7.5There is an out of bound read vulnerability in some verisons of Huawei CloudEngine product. A module does not deal with ...
CVE-2020-35773HIGH8.8The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.
CVE-2020-5807HIGH7.5An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the Factor...
CVE-2020-5802HIGH7.5An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a special...
CVE-2020-5801HIGH7.5An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled ex...
CVE-2020-17533HIGH8.1Apache Accumulo versions 1.5.0 through 1.10.0 and version 2.0.0 do not properly check the return value of some policy en...
CVE-2020-25847HIGH8.8This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP h...
CVE-2020-26287HIGH8.7HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an attacker can ...
CVE-2020-26286HIGH7.5HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an unauthenticat...
CVE-2020-35766HIGH7.8The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack agai...
CVE-2020-35616HIGH7.5An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause ...
CVE-2020-35612HIGH7.5An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validatio...
CVE-2020-35611HIGH7.5An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now