2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27653 | HIGH | 8.3 | 0.8% | Oct 29, 2020 | Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-m... |
| CVE-2020-27652 | HIGH | 8.3 | 0.8% | Oct 29, 2020 | Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-... |
| CVE-2020-27651 | HIGH | 8.1 | 0.8% | Oct 29, 2020 | Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session,... |
| CVE-2020-11616 | HIGH | 7.5 | 1.3% | Oct 29, 2020 | NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which... |
| CVE-2020-11615 | HIGH | 7.5 | 1.2% | Oct 29, 2020 | NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which... |
| CVE-2020-11489 | HIGH | 7.5 | 1.3% | Oct 29, 2020 | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior... |
| CVE-2020-11487 | HIGH | 7.5 | 1.3% | Oct 29, 2020 | NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06... |
| CVE-2020-11485 | HIGH | 8.8 | 0.8% | Oct 29, 2020 | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a Cross-Site Request Forgery (CSRF) ... |
| CVE-2020-27986 | HIGH | 7.5 | 16.2% | Oct 28, 2020 | SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settin... |
| CVE-2020-24713 | HIGH | 7.5 | 1.1% | Oct 28, 2020 | Gophish through 0.10.1 does not invalidate the gophish cookie upon logout. |
| CVE-2020-24707 | HIGH | 7.8 | 1.3% | Oct 28, 2020 | Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content. |
| CVE-2020-24990 | HIGH | 7.5 | 3.6% | Oct 28, 2020 | An issue was discovered in QSC Q-SYS Core Manager 8.2.1. By utilizing the TFTP service running on UDP port 69, a remote ... |
| CVE-2020-26133 | HIGH | 7.8 | 0.3% | Oct 28, 2020 | An issue was discovered in Dual DHCP DNS Server 7.40. Due to insufficient access restrictions in the default installatio... |
| CVE-2020-26132 | HIGH | 7.8 | 0.3% | Oct 28, 2020 | An issue was discovered in Home DNS Server 0.10. Due to insufficient access restrictions in the default installation dir... |
| CVE-2020-26131 | HIGH | 7.8 | 0.4% | Oct 28, 2020 | Issues were discovered in Open DHCP Server (Regular) 1.75 and Open DHCP Server (LDAP Based) 0.1Beta. Due to insufficient... |
| CVE-2020-26130 | HIGH | 7.8 | 0.4% | Oct 28, 2020 | Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient... |
| CVE-2020-25966 | HIGH | 7.5 | 1.4% | Oct 28, 2020 | Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured as... |
| CVE-2020-16262 | HIGH | 7.8 | 0.4% | Oct 28, 2020 | Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation. |
| CVE-2020-16260 | HIGH | 7.5 | 0.9% | Oct 28, 2020 | Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with othe... |
| CVE-2020-16258 | HIGH | 7.1 | 0.4% | Oct 28, 2020 | Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with ... |
| CVE-2020-16256 | HIGH | 8.8 | 0.7% | Oct 28, 2020 | The API on Winston 1.5.4 devices is vulnerable to CSRF. |
| CVE-2020-4767 | HIGH | 7.5 | 1.6% | Oct 28, 2020 | IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial... |
| CVE-2020-15278 | HIGH | 7.5 | 1.1% | Oct 28, 2020 | Red Discord Bot before version 3.4.1 has an unauthorized privilege escalation exploit in the Mod module. This exploit al... |
| CVE-2020-27978 | HIGH | 7.5 | 1.8% | Oct 28, 2020 | Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause ... |
| CVE-2020-27975 | HIGH | 8.8 | 0.6% | Oct 28, 2020 | osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now