2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-35715HIGH8.8Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shel...
CVE-2020-35714HIGH8.8Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via gofor...
CVE-2020-35711HIGH7.5An issue has been discovered in the arc-swap crate before 0.4.8 (and 1.x before 1.1.0) for Rust. Use of arc_swap::access...
CVE-2020-35708HIGH7.2phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Adminis...
CVE-2020-35702HIGH7.8DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE...
CVE-2020-28912HIGH7With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivi...
CVE-2020-11093HIGH7.5Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In Hyperle...
CVE-2020-35693HIGH8.8On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-controlled Bluetooth Lo...
CVE-2020-24658HIGH7.8Arm Compiler 5 through 5.06u6 has an error in a stack protection feature designed to help spot stack-based buffer overfl...
CVE-2020-9200HIGH7.8There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege ...
CVE-2020-9120HIGH7.5CloudEngine 1800V versions V100R019C10SPC500 has a resource management error vulnerability. Remote unauthorized attacker...
CVE-2020-35680HIGH7.5smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of ...
CVE-2020-35679HIGH7.5smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very signif...
CVE-2020-27728HIGH7.5On BIG-IP ASM & Advanced WAF versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, under certain conditions, Ana...
CVE-2020-27723HIGH7.5In versions 14.1.0-14.1.3 and 13.1.0-13.1.3.4, a BIG-IP APM virtual server processing PingAccess requests may lead to a ...
CVE-2020-27720HIGH7.5On BIG-IP LTM/CGNAT version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when processing NAT66 ...
CVE-2020-27717HIGH7.5On BIG-IP DNS 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, undisclosed series ...
CVE-2020-27716HIGH7.5On versions 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when a BIG-IP APM vir...
CVE-2020-27715HIGH7.5On BIG-IP 15.1.0-15.1.0.5 and 14.1.0-14.1.3, crafted TLS request to the BIG-IP management interface via port 443 can cau...
CVE-2020-27714HIGH7.5On the BIG-IP AFM version 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when a Protocol Inspection Profile is att...
CVE-2020-29189HIGH8.1Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read...
CVE-2020-28186HIGH7.3Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functi...
CVE-2020-28169HIGH7The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory ...
CVE-2020-27721HIGH7.5In versions 16.0.0-16.0.0.1, 15.1.0-15.1.1, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, in a B...
CVE-2020-27718HIGH7.5When a BIG-IP ASM or Advanced WAF system running version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3....

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now