2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-24572HIGH8.8An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misco...
CVE-2020-7377HIGH7.5The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path tr...
CVE-2020-24364HIGH8.8MineTime through 1.8.5 allows arbitrary command execution via the notes field in a meeting. Could lead to RCE via meetin...
CVE-2020-7705HIGH8.1This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality ...
CVE-2020-24606HIGH7.5Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU...
CVE-2020-4587HIGH7.8IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based buffer ovreflow, caus...
CVE-2020-14044HIGH7.2** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 ...
CVE-2020-14043HIGH8.8** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 a...
CVE-2020-7831HIGH8.8A vulnerability in the web-based contract management service interface Ebiz4u of INOGARD could allow an victim user to d...
CVE-2020-19891HIGH7.2DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename an...
CVE-2020-19889HIGH8.8DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.
CVE-2020-19886HIGH8.1DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can...
CVE-2020-19878HIGH7.5DBHcms v1.2.0 has a sensitive information leaks vulnerability as there is no security access control in /dbhcms/ext/news...
CVE-2020-14350HIGH7.3It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker wi...
CVE-2020-14349HIGH7.1It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_pat...
CVE-2020-13101HIGH7.5In OASIS Digital Signature Services (DSS) 1.0, an attacker can control the validation outcome (i.e., trigger either a va...
CVE-2020-7711HIGH7.5This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference ca...
CVE-2020-5417HIGH8.8Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also t...
CVE-2020-9063HIGH7.6NCR SelfServ ATMs running APTRA XFS 05.01.00 or earlier do not authenticate or protect the integrity of USB HID communic...
CVE-2020-8623HIGH7.5In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Suppor...
CVE-2020-8621HIGH7.5In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' t...
CVE-2020-8620HIGH7.5In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data...
CVE-2020-10126HIGH7.6NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA),...
CVE-2020-10125HIGH7.6NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acce...
CVE-2020-10124HIGH7.1NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now