2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35610 | HIGH | 7.5 | 1.3% | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the ac... |
| CVE-2020-25507 | HIGH | 7.8 | 0.5% | Dec 28, 2020 | An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivi... |
| CVE-2020-14273 | HIGH | 7.5 | 1.2% | Dec 28, 2020 | HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its publ... |
| CVE-2020-26289 | HIGH | 7.5 | 2.1% | Dec 28, 2020 | date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular ... |
| CVE-2020-24360 | HIGH | 7.4 | 0.7% | Dec 28, 2020 | An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issu... |
| CVE-2020-35627 | HIGH | 8.8 | 2.0% | Dec 28, 2020 | Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that ca... |
| CVE-2020-29160 | HIGH | 7.5 | 0.9% | Dec 28, 2020 | An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a wa... |
| CVE-2020-26032 | HIGH | 7.5 | 1.1% | Dec 28, 2020 | An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in... |
| CVE-2020-29194 | HIGH | 7.5 | 1.2% | Dec 28, 2020 | Panasonic Security System WV-S2231L 4.25 allows a denial of service of the admin control panel (which will require a phy... |
| CVE-2020-28094 | HIGH | 7.5 | 1.2% | Dec 28, 2020 | On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, the default settings for the router speed test contain links to d... |
| CVE-2020-28093 | HIGH | 7.2 | 1.2% | Dec 28, 2020 | On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234. |
| CVE-2020-35736 | HIGH | 7.5 | 15.4% | Dec 27, 2020 | GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.... |
| CVE-2020-29299 | HIGH | 7.2 | 2.3% | Dec 27, 2020 | Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change a... |
| CVE-2020-35728 | HIGH | 8.1 | 12.5% | Dec 27, 2020 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-8290 | HIGH | 7.8 | 0.6% | Dec 27, 2020 | Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit`... |
| CVE-2020-8289 | HIGH | 7.8 | 4.7% | Dec 27, 2020 | Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validat... |
| CVE-2020-35362 | HIGH | 7.5 | 1.6% | Dec 26, 2020 | DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow rem... |
| CVE-2020-35284 | HIGH | 7.5 | 1.6% | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable pa... |
| CVE-2020-35450 | HIGH | 7.5 | 1.4% | Dec 26, 2020 | Gobby 0.4.11 allows a NULL pointer dereference in the D-Bus handler for certain set_language calls. |
| CVE-2020-35359 | HIGH | 7.5 | 4.7% | Dec 26, 2020 | Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the con... |
| CVE-2020-35376 | HIGH | 7.5 | 2.1% | Dec 26, 2020 | Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to... |
| CVE-2020-35388 | HIGH | 7.5 | 1.5% | Dec 26, 2020 | rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in whi... |
| CVE-2020-26766 | HIGH | 8.8 | 0.6% | Dec 26, 2020 | A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login... |
| CVE-2020-25917 | HIGH | 8.8 | 1.2% | Dec 26, 2020 | Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform,... |
| CVE-2020-35716 | HIGH | 7.5 | 3.9% | Dec 26, 2020 | Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segment... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now