2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35715 | HIGH | 8.8 | 3.7% | Dec 26, 2020 | Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shel... |
| CVE-2020-35714 | HIGH | 8.8 | 2.7% | Dec 26, 2020 | Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via gofor... |
| CVE-2020-35711 | HIGH | 7.5 | 1.6% | Dec 25, 2020 | An issue has been discovered in the arc-swap crate before 0.4.8 (and 1.x before 1.1.0) for Rust. Use of arc_swap::access... |
| CVE-2020-35708 | HIGH | 7.2 | 1.5% | Dec 25, 2020 | phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Adminis... |
| CVE-2020-35702 | HIGH | 7.8 | 0.9% | Dec 25, 2020 | DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE... |
| CVE-2020-28912 | HIGH | 7 | 0.4% | Dec 24, 2020 | With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivi... |
| CVE-2020-11093 | HIGH | 7.5 | 0.9% | Dec 24, 2020 | Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In Hyperle... |
| CVE-2020-35693 | HIGH | 8.8 | 0.4% | Dec 24, 2020 | On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-controlled Bluetooth Lo... |
| CVE-2020-24658 | HIGH | 7.8 | 0.3% | Dec 24, 2020 | Arm Compiler 5 through 5.06u6 has an error in a stack protection feature designed to help spot stack-based buffer overfl... |
| CVE-2020-9200 | HIGH | 7.8 | 0.3% | Dec 24, 2020 | There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege ... |
| CVE-2020-9120 | HIGH | 7.5 | 0.7% | Dec 24, 2020 | CloudEngine 1800V versions V100R019C10SPC500 has a resource management error vulnerability. Remote unauthorized attacker... |
| CVE-2020-35680 | HIGH | 7.5 | 3.6% | Dec 24, 2020 | smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of ... |
| CVE-2020-35679 | HIGH | 7.5 | 2.8% | Dec 24, 2020 | smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very signif... |
| CVE-2020-27728 | HIGH | 7.5 | 1.0% | Dec 24, 2020 | On BIG-IP ASM & Advanced WAF versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, under certain conditions, Ana... |
| CVE-2020-27723 | HIGH | 7.5 | 1.0% | Dec 24, 2020 | In versions 14.1.0-14.1.3 and 13.1.0-13.1.3.4, a BIG-IP APM virtual server processing PingAccess requests may lead to a ... |
| CVE-2020-27720 | HIGH | 7.5 | 1.4% | Dec 24, 2020 | On BIG-IP LTM/CGNAT version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when processing NAT66 ... |
| CVE-2020-27717 | HIGH | 7.5 | 1.1% | Dec 24, 2020 | On BIG-IP DNS 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, undisclosed series ... |
| CVE-2020-27716 | HIGH | 7.5 | 1.3% | Dec 24, 2020 | On versions 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when a BIG-IP APM vir... |
| CVE-2020-27715 | HIGH | 7.5 | 1.1% | Dec 24, 2020 | On BIG-IP 15.1.0-15.1.0.5 and 14.1.0-14.1.3, crafted TLS request to the BIG-IP management interface via port 443 can cau... |
| CVE-2020-27714 | HIGH | 7.5 | 1.0% | Dec 24, 2020 | On the BIG-IP AFM version 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when a Protocol Inspection Profile is att... |
| CVE-2020-29189 | HIGH | 8.1 | 1.2% | Dec 24, 2020 | Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read... |
| CVE-2020-28186 | HIGH | 7.3 | 4.1% | Dec 24, 2020 | Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functi... |
| CVE-2020-28169 | HIGH | 7 | 1.2% | Dec 24, 2020 | The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory ... |
| CVE-2020-27721 | HIGH | 7.5 | 1.0% | Dec 24, 2020 | In versions 16.0.0-16.0.0.1, 15.1.0-15.1.1, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, in a B... |
| CVE-2020-27718 | HIGH | 7.5 | 1.0% | Dec 24, 2020 | When a BIG-IP ASM or Advanced WAF system running version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now