2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-5416MEDIUM6.5Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in fro...
CVE-2020-9062MEDIUM5.3Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify th...
CVE-2020-8624MEDIUM4.3In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S...
CVE-2020-8622MEDIUM6.5In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supporte...
CVE-2020-8227MEDIUM6.8Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Serv...
CVE-2020-8189MEDIUM5.4A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when ...
CVE-2020-15858MEDIUM6.4Some devices of Thales DIS (formerly Gemalto, formerly Cinterion) allow Directory Traversal by physically proximate atta...
CVE-2020-10123MEDIUM5.3The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate sessio...
CVE-2020-24591MEDIUM6.5The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manage...
CVE-2020-14201MEDIUM6.5Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitr...
CVE-2020-5775MEDIUM5.8Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas appli...
CVE-2020-3975MEDIUM5.4VMware App Volumes 2.x prior to 2.18.6 and VMware App Volumes 4 prior to 2006 contain a Stored Cross-Site Scripting (XSS...
CVE-2020-20633MEDIUM5.4ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Conse...
CVE-2020-7923MEDIUM6.5A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which vi...
CVE-2020-20634MEDIUM6.5Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exp...
CVE-2020-10290MEDIUM6.8Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restr...
CVE-2020-9246MEDIUM6.5FusionCompute 8.0.0 has an information leak vulnerability. A module does not launch strict access control and informatio...
CVE-2020-9104MEDIUM4.3HUAWEI P30 smartphones with Versions earlier than 10.1.0.123(C431E22R2P5),Versions earlier than 10.1.0.123(C432E22R2P5),...
CVE-2020-9096MEDIUM5.5HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. S...
CVE-2020-9095MEDIUM5.5HUAWEI P30 Pro smartphone with Versions earlier than 10.1.0.160(C00E160R2P8) has an integer overflow vulnerability. Some...
CVE-2020-24585MEDIUM5.3An issue was discovered in the DTLS handshake implementation in wolfSSL before 4.5.0. Clear DTLS application_data messag...
CVE-2020-3976MEDIUM5.3VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication serv...
CVE-2020-16239MEDIUM4.9When an actor claims to have a given identity, Philips SureSigns VS4, A.07.107 and prior does not prove or insufficie...
CVE-2020-14518MEDIUM5.3Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.
CVE-2020-7310MEDIUM6.9Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 all...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now