2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-35610HIGH7.5An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the ac...
CVE-2020-25507HIGH7.8An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivi...
CVE-2020-14273HIGH7.5HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its publ...
CVE-2020-26289HIGH7.5date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular ...
CVE-2020-24360HIGH7.4An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issu...
CVE-2020-35627HIGH8.8Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that ca...
CVE-2020-29160HIGH7.5An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a wa...
CVE-2020-26032HIGH7.5An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in...
CVE-2020-29194HIGH7.5Panasonic Security System WV-S2231L 4.25 allows a denial of service of the admin control panel (which will require a phy...
CVE-2020-28094HIGH7.5On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, the default settings for the router speed test contain links to d...
CVE-2020-28093HIGH7.2On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234.
CVE-2020-35736HIGH7.5GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path....
CVE-2020-29299HIGH7.2Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change a...
CVE-2020-35728HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-8290HIGH7.8Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit`...
CVE-2020-8289HIGH7.8Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validat...
CVE-2020-35362HIGH7.5DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow rem...
CVE-2020-35284HIGH7.5Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable pa...
CVE-2020-35450HIGH7.5Gobby 0.4.11 allows a NULL pointer dereference in the D-Bus handler for certain set_language calls.
CVE-2020-35359HIGH7.5Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the con...
CVE-2020-35376HIGH7.5Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to...
CVE-2020-35388HIGH7.5rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in whi...
CVE-2020-26766HIGH8.8A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login...
CVE-2020-25917HIGH8.8Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform,...
CVE-2020-35716HIGH7.5Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segment...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now