Skip to main content

Year archive

CVEs published in 2020

Archive summary

18,322 CVEs published in 2020 — 2,625 Critical, 7,666 High, 7,546 Medium, 485 Low, 0 Unrated.

CVE-2020-9137

Published Dec 24, 2020

There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a…

CVSS 6.7 · Medium

CVE-2020-9120

Published Dec 24, 2020

CloudEngine 1800V versions V100R019C10SPC500 has a resource management error vulnerability. Remote unauthorized attackers could send specific types of messages to the device, resu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35680

Published Dec 24, 2020

smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35679

Published Dec 24, 2020

smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that perform…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35659

Published Dec 24, 2020

The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitra…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27729

Published Dec 24, 2020

In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an undisclosed link on the BIG-IP APM virtual server allows a m…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27726

Published Dec 24, 2020

In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a reflected cross-site scripting (XSS) vulnerability exists in the resource info…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27723

Published Dec 24, 2020

In versions 14.1.0-14.1.3 and 13.1.0-13.1.3.4, a BIG-IP APM virtual server processing PingAccess requests may lead to a restart of the Traffic Management Microkernel (TMM) process.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27722

Published Dec 24, 2020

In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin does not observe plugin flow-control protocol causing excessiv…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27717

Published Dec 24, 2020

On BIG-IP DNS 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, undisclosed series of DNS requests may cause TMM to restart and generate a cor…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27716

Published Dec 24, 2020

On versions 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when a BIG-IP APM virtual server processes traffic of an undisclosed nature, the…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-27714

Published Dec 24, 2020

On the BIG-IP AFM version 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when a Protocol Inspection Profile is attached to a FastL4 virtual server with the protocol field co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29189

Published Dec 24, 2020

Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read-only restriction and obtain full access to any folder with…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28190

Published Dec 24, 2020

TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP). Man-in-the-middle attackers are able to intercept these…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28188

Published Dec 24, 2020

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2020-28187

Published Dec 24, 2020

Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within the filesystem via the (1) f…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28186

Published Dec 24, 2020

Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28185

Published Dec 24, 2020

User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28184

Published Dec 24, 2020

Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitrary web script or HTML via the mod parameter to /module/ind…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 18,322 CVEsPage 16 of 733