2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9062MEDIUM5.3Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify th...
CVE-2020-8624MEDIUM4.3In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S...
CVE-2020-8623HIGH7.5In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Suppor...
CVE-2020-8622MEDIUM6.5In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supporte...
CVE-2020-8621HIGH7.5In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' t...
CVE-2020-8620HIGH7.5In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data...
CVE-2020-8234CRITICAL9.8A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cooki...
CVE-2020-8227MEDIUM6.8Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Serv...
CVE-2020-8189MEDIUM5.4A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when ...
CVE-2020-15858MEDIUM6.4Some devices of Thales DIS (formerly Gemalto, formerly Cinterion) allow Directory Traversal by physically proximate atta...
CVE-2020-10126HIGH7.6NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA),...
CVE-2020-10125HIGH7.6NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acce...
CVE-2020-10124HIGH7.1NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between t...
CVE-2020-10123MEDIUM5.3The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate sessio...
CVE-2020-24591MEDIUM6.5The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manage...
CVE-2020-24590CRITICAL9.1The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
CVE-2020-24589CRITICAL9.1The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection...
CVE-2020-14201MEDIUM6.5Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitr...
CVE-2020-5775MEDIUM5.8Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas appli...
CVE-2020-3975MEDIUM5.4VMware App Volumes 2.x prior to 2.18.6 and VMware App Volumes 4 prior to 2006 contain a Stored Cross-Site Scripting (XSS...
CVE-2020-15147HIGH8.5Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Streams module. This exp...
CVE-2020-15140CRITICAL9.6In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Di...
CVE-2020-20633MEDIUM5.4ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Conse...
CVE-2020-7923MEDIUM6.5A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which vi...
CVE-2020-24057HIGH8.8The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows th...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now