2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4908MEDIUM5.3IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release in...
CVE-2020-4907MEDIUM5.3IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow a remote attacker to obtain se...
CVE-2020-4906LOW3.3IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally whic...
CVE-2020-4905MEDIUM5.9IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an remote attacker to obtain s...
CVE-2020-4904MEDIUM6.5IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forger...
CVE-2020-4658MEDIUM6.1IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2020-4657MEDIUM6.1IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnera...
CVE-2020-28931HIGH8.8Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthen...
CVE-2020-28930MEDIUM5.4A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON...
CVE-2020-28929CRITICAL9.8Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated at...
CVE-2020-26274HIGH8.8In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fix...
CVE-2020-7781CRITICAL9.8This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The foll...
CVE-2020-35133HIGH7.5irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32...
CVE-2020-7837HIGH8.8An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportD...
CVE-2020-5360HIGH7.5Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthent...
CVE-2020-5359MEDIUM5.8Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An una...
CVE-2020-26198MEDIUM6.1Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in th...
CVE-2020-4008LOW3.6The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure wa...
CVE-2020-29607HIGH7.2A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access...
CVE-2020-25622HIGH8.8An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.
CVE-2020-25621HIGH8.4An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security...
CVE-2020-25620HIGH7.8An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accou...
CVE-2020-14254HIGH7.5TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enab...
CVE-2020-14248MEDIUM5.3BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause ...
CVE-2020-29363HIGH7.5An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC p...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now