2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25204MEDIUM5.5The God Kings application 0.60.1 for Android exposes a broadcast receiver to other apps called com.innogames.core.fronte...
CVE-2020-24990HIGH7.5An issue was discovered in QSC Q-SYS Core Manager 8.2.1. By utilizing the TFTP service running on UDP port 69, a remote ...
CVE-2020-26133HIGH7.8An issue was discovered in Dual DHCP DNS Server 7.40. Due to insufficient access restrictions in the default installatio...
CVE-2020-26132HIGH7.8An issue was discovered in Home DNS Server 0.10. Due to insufficient access restrictions in the default installation dir...
CVE-2020-26131HIGH7.8Issues were discovered in Open DHCP Server (Regular) 1.75 and Open DHCP Server (LDAP Based) 0.1Beta. Due to insufficient...
CVE-2020-26130HIGH7.8Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient...
CVE-2020-25966HIGH7.5Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured as...
CVE-2020-16263CRITICAL9.1Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewe...
CVE-2020-16262HIGH7.8Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.
CVE-2020-16261MEDIUM6.8Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.
CVE-2020-16260HIGH7.5Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with othe...
CVE-2020-16259CRITICAL9.8Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents ...
CVE-2020-16258HIGH7.1Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with ...
CVE-2020-16256HIGH8.8The API on Winston 1.5.4 devices is vulnerable to CSRF.
CVE-2020-4782MEDIUM6.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the sys...
CVE-2020-4767HIGH7.5IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial...
CVE-2020-16257CRITICAL9.8Winston 1.5.4 devices are vulnerable to command injection via the API.
CVE-2020-15278HIGH7.5Red Discord Bot before version 3.4.1 has an unauthorized privilege escalation exploit in the Mod module. This exploit al...
CVE-2020-27978HIGH7.5Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause ...
CVE-2020-27976CRITICAL9.8osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter ...
CVE-2020-27975HIGH8.8osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
CVE-2020-27974MEDIUM6.1NeoPost Mail Accounting Software Pro 5.0.6 allows php/Commun/FUS_SCM_BlockStart.php?code= XSS.
CVE-2020-24303MEDIUM6.1Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
CVE-2020-22552HIGH7.5The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-un...
CVE-2020-8263MEDIUM5.4A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now