2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35784 | HIGH | 7.2 | 0.8% | Dec 30, 2020 | Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0... |
| CVE-2020-35782 | HIGH | 8.1 | 1.6% | Dec 30, 2020 | Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0... |
| CVE-2020-35779 | HIGH | 8.6 | 0.9% | Dec 30, 2020 | NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service. |
| CVE-2020-35778 | HIGH | 8.8 | 0.4% | Dec 30, 2020 | Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36. |
| CVE-2020-35777 | HIGH | 8.4 | 0.8% | Dec 30, 2020 | NETGEAR DGN2200v1 devices before v1.0.0.58 are affected by command injection. |
| CVE-2020-10209 | HIGH | 8.1 | 2.7% | Dec 30, 2020 | Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx ser... |
| CVE-2020-27645 | HIGH | 8.8 | 1.2% | Dec 29, 2020 | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\... |
| CVE-2020-27644 | HIGH | 8.8 | 1.2% | Dec 29, 2020 | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\... |
| CVE-2020-16268 | HIGH | 8.8 | 1.3% | Dec 29, 2020 | The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevate... |
| CVE-2020-9223 | HIGH | 7.5 | 0.9% | Dec 29, 2020 | There is a denial of service vulnerability in some Huawei smartphones. Due to the improper processing of received abnorm... |
| CVE-2020-9207 | HIGH | 7.8 | 0.6% | Dec 29, 2020 | There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not veri... |
| CVE-2020-9124 | HIGH | 7.5 | 0.9% | Dec 29, 2020 | There is a memory leak vulnerability in some versions of Huawei CloudEngine product. An unauthenticated, remote attacker... |
| CVE-2020-9094 | HIGH | 7.5 | 0.7% | Dec 29, 2020 | There is an out of bound read vulnerability in some verisons of Huawei CloudEngine product. A module does not deal with ... |
| CVE-2020-35773 | HIGH | 8.8 | 1.0% | Dec 29, 2020 | The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF. |
| CVE-2020-5807 | HIGH | 7.5 | 33.8% | Dec 29, 2020 | An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the Factor... |
| CVE-2020-5802 | HIGH | 7.5 | 38.8% | Dec 29, 2020 | An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a special... |
| CVE-2020-5801 | HIGH | 7.5 | 25.2% | Dec 29, 2020 | An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled ex... |
| CVE-2020-17533 | HIGH | 8.1 | 3.7% | Dec 29, 2020 | Apache Accumulo versions 1.5.0 through 1.10.0 and version 2.0.0 do not properly check the return value of some policy en... |
| CVE-2020-25847 | HIGH | 8.8 | 2.5% | Dec 29, 2020 | This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP h... |
| CVE-2020-26287 | HIGH | 8.7 | 1.4% | Dec 29, 2020 | HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an attacker can ... |
| CVE-2020-26286 | HIGH | 7.5 | 1.4% | Dec 29, 2020 | HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an unauthenticat... |
| CVE-2020-35766 | HIGH | 7.8 | 0.5% | Dec 28, 2020 | The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack agai... |
| CVE-2020-35616 | HIGH | 7.5 | 6.1% | Dec 28, 2020 | An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause ... |
| CVE-2020-35612 | HIGH | 7.5 | 1.6% | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validatio... |
| CVE-2020-35611 | HIGH | 7.5 | 1.3% | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now