2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-27653HIGH8.3Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-m...
CVE-2020-27652HIGH8.3Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-...
CVE-2020-27651HIGH8.1Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session,...
CVE-2020-11616HIGH7.5NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which...
CVE-2020-11615HIGH7.5NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which...
CVE-2020-11489HIGH7.5NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior...
CVE-2020-11487HIGH7.5NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06...
CVE-2020-11485HIGH8.8NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a Cross-Site Request Forgery (CSRF) ...
CVE-2020-27986HIGH7.5SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settin...
CVE-2020-24713HIGH7.5Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.
CVE-2020-24707HIGH7.8Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.
CVE-2020-24990HIGH7.5An issue was discovered in QSC Q-SYS Core Manager 8.2.1. By utilizing the TFTP service running on UDP port 69, a remote ...
CVE-2020-26133HIGH7.8An issue was discovered in Dual DHCP DNS Server 7.40. Due to insufficient access restrictions in the default installatio...
CVE-2020-26132HIGH7.8An issue was discovered in Home DNS Server 0.10. Due to insufficient access restrictions in the default installation dir...
CVE-2020-26131HIGH7.8Issues were discovered in Open DHCP Server (Regular) 1.75 and Open DHCP Server (LDAP Based) 0.1Beta. Due to insufficient...
CVE-2020-26130HIGH7.8Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient...
CVE-2020-25966HIGH7.5Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured as...
CVE-2020-16262HIGH7.8Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.
CVE-2020-16260HIGH7.5Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with othe...
CVE-2020-16258HIGH7.1Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with ...
CVE-2020-16256HIGH8.8The API on Winston 1.5.4 devices is vulnerable to CSRF.
CVE-2020-4767HIGH7.5IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial...
CVE-2020-15278HIGH7.5Red Discord Bot before version 3.4.1 has an unauthorized privilege escalation exploit in the Mod module. This exploit al...
CVE-2020-27978HIGH7.5Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause ...
CVE-2020-27975HIGH8.8osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now