Skip to main content

Year archive

CVEs published in 2020

Archive summary

18,322 CVEs published in 2020 — 2,625 Critical, 7,666 High, 7,546 Medium, 485 Low, 0 Unrated.

CVE-2020-35716

Published Dec 26, 2020

Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segmentation fault) via a long /goform/langSwitch langSelectionOnl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35715

Published Dec 26, 2020

Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters in a filename to the upload_settings.cgi p…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35714

Published Dec 26, 2020

Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pin…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35713

Published Dec 26, 2020

Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35711

Published Dec 25, 2020

An issue has been discovered in the arc-swap crate before 0.4.8 (and 1.x before 1.1.0) for Rust. Use of arc_swap::access::Map with the Constant test helper (or with a user-supplie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35710

Published Dec 25, 2020

Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35709

Published Dec 25, 2020

bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35708

Published Dec 25, 2020

phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35702

Published Dec 25, 2020

DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26282

Published Dec 24, 2020

BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Proxy works well as a standalone p…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-29474

Published Dec 24, 2020

EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitra…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-29247

Published Dec 24, 2020

WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywords and each time any user will visit the website…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28912

Published Dec 24, 2020

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machin…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11093

Published Dec 24, 2020

Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In Hyperledger Indy before version 1.12.4, there is lack of signature…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24658

Published Dec 24, 2020

Arm Compiler 5 through 5.06u6 has an error in a stack protection feature designed to help spot stack-based buffer overflows in local arrays. When this feature is enabled, a protec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9202

Published Dec 24, 2020

There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to the improper storage of some information in certain specific…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9200

Published Dec 24, 2020

There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to i…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 351-375 of 18,322 CVEsPage 15 of 733