2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-20183HIGH7.5Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier al...
CVE-2020-16104HIGH7.2SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit...
CVE-2020-16103HIGH8.8Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote ...
CVE-2020-16102HIGH8.2Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to cr...
CVE-2020-28858HIGH8.8OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the applica...
CVE-2020-28856HIGH7.5OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP ...
CVE-2020-35382HIGH7.2SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user.
CVE-2020-5665HIGH7.4Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and e...
CVE-2020-5635HIGH8.8Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially craft...
CVE-2020-35235HIGH8.8vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder cod...
CVE-2020-35234HIGH7.5The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in De...
CVE-2020-29669HIGH8.8In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This pr...
CVE-2020-29654HIGH7.8Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.
CVE-2020-24340HIGH7.5An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The code that processes DNS responses in pico_mdns_hand...
CVE-2020-24339HIGH7.5An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The DNS domain name record decompression functionality ...
CVE-2020-24337HIGH7.5An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. When an unsupported TCP option with zero length is prov...
CVE-2020-24334HIGH8.2The code that processes DNS responses in uIP through 1.0, as used in Contiki and Contiki-NG, does not check whether the ...
CVE-2020-17469HIGH7.5An issue was discovered in FNET through 4.6.4. The code for IPv6 fragment reassembly tries to access a previous fragment...
CVE-2020-17468HIGH7.5An issue was discovered in FNET through 4.6.4. The code for processing the hop-by-hop header (in the IPv6 extension head...
CVE-2020-17445HIGH7.5An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 destination options does not check for a vali...
CVE-2020-17444HIGH7.5An issue was discovered in picoTCP 1.7.0. The routine for processing the next header field (and deducing whether the IPv...
CVE-2020-17443HIGH7.5An issue was discovered in picoTCP 1.7.0. The code for creating an ICMPv6 echo replies doesn't check whether the ICMPv6 ...
CVE-2020-17442HIGH7.5An issue was discovered in picoTCP 1.7.0. The code for parsing the hop-by-hop IPv6 extension headers does not validate t...
CVE-2020-17440HIGH7.5An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets...
CVE-2020-17439HIGH8.3An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now