2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-26819HIGH8.8SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user...
CVE-2020-26818HIGH8.8SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user...
CVE-2020-26817HIGH7.8SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sourc...
CVE-2020-26815HIGH8.6SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send...
CVE-2020-26810HIGH7.5SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to ...
CVE-2020-26808HIGH7.2SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 a...
CVE-2020-28267HIGH7.5Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and m...
CVE-2020-0451HIGH8.8In sbrDecoder_AssignQmfChannels2SbrChannels of sbrdecoder.cpp, there is a possible out of bounds write due to a heap buf...
CVE-2020-0449HIGH8.8In btm_sec_disconnected of btm_sec.cc, there is a possible memory corruption due to a use after free. This could lead to...
CVE-2020-0442HIGH7.5In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation....
CVE-2020-0441HIGH7.5In Message and toBundle of Notification.java, there is a possible resource exhaustion due to improper input validation. ...
CVE-2020-0439HIGH7.8In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permiss...
CVE-2020-0438HIGH7.8In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data...
CVE-2020-0418HIGH7.8In getPermissionInfosForGroup of Utils.java, there is a logic error. This could lead to local escalation of privilege wi...
CVE-2020-0409HIGH7.8In create of FileMap.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local e...
CVE-2020-27694HIGH8.8Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 has updated a specific critical library that may ...
CVE-2020-27016HIGH8.8Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a cross-site request forgery (CS...
CVE-2020-28373HIGH8.8upnpd on certain NETGEAR devices allows remote (LAN) attackers to execute arbitrary code via a stack-based buffer overfl...
CVE-2020-4759HIGH7.8IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute ...
CVE-2020-27977HIGH7.8CapaSystems CapaInstaller before 6.0.101 does not properly assign, modify, or check privileges for an actor who attempts...
CVE-2020-23140HIGH8.1Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user...
CVE-2020-14366HIGH7.5A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible b...
CVE-2020-8268HIGH7.5Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify metho...
CVE-2020-24400HIGH7.1Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensiti...
CVE-2020-7764HIGH7.5This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now