Skip to main content

Year archive

CVEs published in 2020

Archive summary

18,322 CVEs published in 2020 — 2,625 Critical, 7,666 High, 7,546 Medium, 485 Low, 0 Unrated.

CVE-2020-27724

Published Dec 24, 2020

In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on systems running more than one TM…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35677

Published Dec 24, 2020

BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEditGroup.php to create a new group, resul…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35676

Published Dec 24, 2020

BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration functionality. As such, an attacker can inp…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35669

Published Dec 24, 2020

An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2505

Published Dec 24, 2020

If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-2504

Published Dec 24, 2020

If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 a…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2503

Published Dec 24, 2020

If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-2499

Published Dec 24, 2020

A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded passwor…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35668

Published Dec 23, 2020

RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as an alias that has not yet been introduc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35666

Published Dec 23, 2020

Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as de…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35665

Published Dec 23, 2020

An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creat…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35370

Published Dec 23, 2020

A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically crafted request to override the specific file in server with m…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35269

Published Dec 23, 2020

Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 401-425 of 18,322 CVEsPage 17 of 733