2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-20183 | HIGH | 7.5 | 1.0% | Dec 14, 2020 | Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier al... |
| CVE-2020-16104 | HIGH | 7.2 | 0.9% | Dec 14, 2020 | SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit... |
| CVE-2020-16103 | HIGH | 8.8 | 2.2% | Dec 14, 2020 | Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote ... |
| CVE-2020-16102 | HIGH | 8.2 | 1.0% | Dec 14, 2020 | Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to cr... |
| CVE-2020-28858 | HIGH | 8.8 | 1.1% | Dec 14, 2020 | OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the applica... |
| CVE-2020-28856 | HIGH | 7.5 | 2.5% | Dec 14, 2020 | OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP ... |
| CVE-2020-35382 | HIGH | 7.2 | 1.0% | Dec 14, 2020 | SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user. |
| CVE-2020-5665 | HIGH | 7.4 | 1.0% | Dec 14, 2020 | Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and e... |
| CVE-2020-5635 | HIGH | 8.8 | 1.0% | Dec 14, 2020 | Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially craft... |
| CVE-2020-35235 | HIGH | 8.8 | 18.0% | Dec 14, 2020 | vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder cod... |
| CVE-2020-35234 | HIGH | 7.5 | 63.4% | Dec 14, 2020 | The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in De... |
| CVE-2020-29669 | HIGH | 8.8 | 4.9% | Dec 14, 2020 | In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This pr... |
| CVE-2020-29654 | HIGH | 7.8 | 0.4% | Dec 12, 2020 | Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account. |
| CVE-2020-24340 | HIGH | 7.5 | 2.8% | Dec 11, 2020 | An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The code that processes DNS responses in pico_mdns_hand... |
| CVE-2020-24339 | HIGH | 7.5 | 2.8% | Dec 11, 2020 | An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The DNS domain name record decompression functionality ... |
| CVE-2020-24337 | HIGH | 7.5 | 2.8% | Dec 11, 2020 | An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. When an unsupported TCP option with zero length is prov... |
| CVE-2020-24334 | HIGH | 8.2 | 2.4% | Dec 11, 2020 | The code that processes DNS responses in uIP through 1.0, as used in Contiki and Contiki-NG, does not check whether the ... |
| CVE-2020-17469 | HIGH | 7.5 | 3.0% | Dec 11, 2020 | An issue was discovered in FNET through 4.6.4. The code for IPv6 fragment reassembly tries to access a previous fragment... |
| CVE-2020-17468 | HIGH | 7.5 | 3.0% | Dec 11, 2020 | An issue was discovered in FNET through 4.6.4. The code for processing the hop-by-hop header (in the IPv6 extension head... |
| CVE-2020-17445 | HIGH | 7.5 | 2.9% | Dec 11, 2020 | An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 destination options does not check for a vali... |
| CVE-2020-17444 | HIGH | 7.5 | 2.8% | Dec 11, 2020 | An issue was discovered in picoTCP 1.7.0. The routine for processing the next header field (and deducing whether the IPv... |
| CVE-2020-17443 | HIGH | 7.5 | 2.8% | Dec 11, 2020 | An issue was discovered in picoTCP 1.7.0. The code for creating an ICMPv6 echo replies doesn't check whether the ICMPv6 ... |
| CVE-2020-17442 | HIGH | 7.5 | 2.9% | Dec 11, 2020 | An issue was discovered in picoTCP 1.7.0. The code for parsing the hop-by-hop IPv6 extension headers does not validate t... |
| CVE-2020-17440 | HIGH | 7.5 | 2.8% | Dec 11, 2020 | An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets... |
| CVE-2020-17439 | HIGH | 8.3 | 3.1% | Dec 11, 2020 | An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now