2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24572 | HIGH | 8.8 | 6.8% | Aug 24, 2020 | An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misco... |
| CVE-2020-7377 | HIGH | 7.5 | 1.1% | Aug 24, 2020 | The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path tr... |
| CVE-2020-24364 | HIGH | 8.8 | 2.6% | Aug 24, 2020 | MineTime through 1.8.5 allows arbitrary command execution via the notes field in a meeting. Could lead to RCE via meetin... |
| CVE-2020-7705 | HIGH | 8.1 | 1.2% | Aug 24, 2020 | This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality ... |
| CVE-2020-24606 | HIGH | 7.5 | 5.2% | Aug 24, 2020 | Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU... |
| CVE-2020-4587 | HIGH | 7.8 | 0.3% | Aug 24, 2020 | IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based buffer ovreflow, caus... |
| CVE-2020-14044 | HIGH | 7.2 | 3.2% | Aug 24, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 ... |
| CVE-2020-14043 | HIGH | 8.8 | 1.5% | Aug 24, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 a... |
| CVE-2020-7831 | HIGH | 8.8 | 0.9% | Aug 24, 2020 | A vulnerability in the web-based contract management service interface Ebiz4u of INOGARD could allow an victim user to d... |
| CVE-2020-19891 | HIGH | 7.2 | 1.4% | Aug 24, 2020 | DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename an... |
| CVE-2020-19889 | HIGH | 8.8 | 0.5% | Aug 24, 2020 | DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user. |
| CVE-2020-19886 | HIGH | 8.1 | 0.4% | Aug 24, 2020 | DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can... |
| CVE-2020-19878 | HIGH | 7.5 | 1.5% | Aug 24, 2020 | DBHcms v1.2.0 has a sensitive information leaks vulnerability as there is no security access control in /dbhcms/ext/news... |
| CVE-2020-14350 | HIGH | 7.3 | 0.5% | Aug 24, 2020 | It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker wi... |
| CVE-2020-14349 | HIGH | 7.1 | 2.2% | Aug 24, 2020 | It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_pat... |
| CVE-2020-13101 | HIGH | 7.5 | 0.7% | Aug 24, 2020 | In OASIS Digital Signature Services (DSS) 1.0, an attacker can control the validation outcome (i.e., trigger either a va... |
| CVE-2020-7711 | HIGH | 7.5 | 1.8% | Aug 23, 2020 | This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference ca... |
| CVE-2020-5417 | HIGH | 8.8 | 1.0% | Aug 21, 2020 | Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also t... |
| CVE-2020-9063 | HIGH | 7.6 | 0.7% | Aug 21, 2020 | NCR SelfServ ATMs running APTRA XFS 05.01.00 or earlier do not authenticate or protect the integrity of USB HID communic... |
| CVE-2020-8623 | HIGH | 7.5 | 6.3% | Aug 21, 2020 | In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Suppor... |
| CVE-2020-8621 | HIGH | 7.5 | 2.9% | Aug 21, 2020 | In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' t... |
| CVE-2020-8620 | HIGH | 7.5 | 3.7% | Aug 21, 2020 | In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data... |
| CVE-2020-10126 | HIGH | 7.6 | 0.3% | Aug 21, 2020 | NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA),... |
| CVE-2020-10125 | HIGH | 7.6 | 0.2% | Aug 21, 2020 | NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acce... |
| CVE-2020-10124 | HIGH | 7.1 | 0.7% | Aug 21, 2020 | NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now