2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4908 | MEDIUM | 5.3 | 1.1% | Dec 16, 2020 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release in... |
| CVE-2020-4907 | MEDIUM | 5.3 | 1.3% | Dec 16, 2020 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow a remote attacker to obtain se... |
| CVE-2020-4906 | LOW | 3.3 | 0.3% | Dec 16, 2020 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally whic... |
| CVE-2020-4905 | MEDIUM | 5.9 | 1.3% | Dec 16, 2020 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an remote attacker to obtain s... |
| CVE-2020-4904 | MEDIUM | 6.5 | 0.5% | Dec 16, 2020 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forger... |
| CVE-2020-4658 | MEDIUM | 6.1 | 0.7% | Dec 16, 2020 | IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2020-4657 | MEDIUM | 6.1 | 0.7% | Dec 16, 2020 | IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnera... |
| CVE-2020-28931 | HIGH | 8.8 | 0.5% | Dec 16, 2020 | Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthen... |
| CVE-2020-28930 | MEDIUM | 5.4 | 0.6% | Dec 16, 2020 | A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON... |
| CVE-2020-28929 | CRITICAL | 9.8 | 1.2% | Dec 16, 2020 | Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated at... |
| CVE-2020-26274 | HIGH | 8.8 | 2.7% | Dec 16, 2020 | In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fix... |
| CVE-2020-7781 | CRITICAL | 9.8 | 2.0% | Dec 16, 2020 | This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The foll... |
| CVE-2020-35133 | HIGH | 7.5 | 4.4% | Dec 16, 2020 | irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32... |
| CVE-2020-7837 | HIGH | 8.8 | 0.7% | Dec 16, 2020 | An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportD... |
| CVE-2020-5360 | HIGH | 7.5 | 2.2% | Dec 16, 2020 | Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthent... |
| CVE-2020-5359 | MEDIUM | 5.8 | 1.1% | Dec 16, 2020 | Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An una... |
| CVE-2020-26198 | MEDIUM | 6.1 | 1.0% | Dec 16, 2020 | Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in th... |
| CVE-2020-4008 | LOW | 3.6 | 0.2% | Dec 16, 2020 | The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure wa... |
| CVE-2020-29607 | HIGH | 7.2 | 33.4% | Dec 16, 2020 | A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access... |
| CVE-2020-25622 | HIGH | 8.8 | 0.9% | Dec 16, 2020 | An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF. |
| CVE-2020-25621 | HIGH | 8.4 | 0.5% | Dec 16, 2020 | An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security... |
| CVE-2020-25620 | HIGH | 7.8 | 0.4% | Dec 16, 2020 | An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accou... |
| CVE-2020-14254 | HIGH | 7.5 | 0.6% | Dec 16, 2020 | TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enab... |
| CVE-2020-14248 | MEDIUM | 5.3 | 0.7% | Dec 16, 2020 | BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause ... |
| CVE-2020-29363 | HIGH | 7.5 | 3.5% | Dec 16, 2020 | An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC p... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now