2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-9278CRITICAL9.1An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by...
CVE-2020-9277CRITICAL9.8An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modul...
CVE-2020-9275CRITICAL9.8An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote...
CVE-2020-11928CRITICAL9.8In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta...
CVE-2020-11895CRITICAL9.1Ming (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c.
CVE-2020-11894CRITICAL9.1Ming (aka libming) 0.4.8 has a heap-based buffer over-read (8 bytes) in the function decompileIF() in decompile.c.
CVE-2020-0073CRITICAL9.8In rw_t2t_handle_tlv_detect_rsp of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds check...
CVE-2020-0072CRITICAL9.8In rw_t2t_handle_tlv_detect_rsp of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds check...
CVE-2020-0071CRITICAL9.8In rw_t2t_extract_default_locks_info of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds ...
CVE-2020-0070CRITICAL9.8In rw_t2t_update_lock_attributes of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds chec...
CVE-2020-11878CRITICAL9.8The Jitsi Meet (aka docker-jitsi-meet) stack on Docker before stable-4384-1 uses default passwords (such as passw0rd) fo...
CVE-2020-11873CRITICAL9.8An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A stack-based buffer ove...
CVE-2020-10377CRITICAL9.8A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated att...
CVE-2020-10211CRITICAL9.8A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthent...
CVE-2020-7485CRITICAL9.8**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier c...
CVE-2020-7224CRITICAL9.8The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered...
CVE-2020-7114CRITICAL9.8A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, ...
CVE-2020-1964CRITICAL9.8It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not ...
CVE-2020-11820CRITICAL9.8Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the entities_id parameter...
CVE-2020-11819CRITICAL9.8In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve...
CVE-2020-11816CRITICAL9.8Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the reports_id (POST) par...
CVE-2020-11815CRITICAL9.8In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a re...
CVE-2020-11812CRITICAL9.8Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the filters[0][value] or ...
CVE-2020-11811CRITICAL9.8In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability w...
CVE-2020-3653CRITICAL9.1Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from users...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now