2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26819 | HIGH | 8.8 | 0.9% | Nov 10, 2020 | SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user... |
| CVE-2020-26818 | HIGH | 8.8 | 1.1% | Nov 10, 2020 | SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user... |
| CVE-2020-26817 | HIGH | 7.8 | 1.2% | Nov 10, 2020 | SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sourc... |
| CVE-2020-26815 | HIGH | 8.6 | 1.4% | Nov 10, 2020 | SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send... |
| CVE-2020-26810 | HIGH | 7.5 | 1.1% | Nov 10, 2020 | SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to ... |
| CVE-2020-26808 | HIGH | 7.2 | 3.0% | Nov 10, 2020 | SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 a... |
| CVE-2020-28267 | HIGH | 7.5 | 2.2% | Nov 10, 2020 | Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and m... |
| CVE-2020-0451 | HIGH | 8.8 | 1.9% | Nov 10, 2020 | In sbrDecoder_AssignQmfChannels2SbrChannels of sbrdecoder.cpp, there is a possible out of bounds write due to a heap buf... |
| CVE-2020-0449 | HIGH | 8.8 | 1.3% | Nov 10, 2020 | In btm_sec_disconnected of btm_sec.cc, there is a possible memory corruption due to a use after free. This could lead to... |
| CVE-2020-0442 | HIGH | 7.5 | 1.0% | Nov 10, 2020 | In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation.... |
| CVE-2020-0441 | HIGH | 7.5 | 1.1% | Nov 10, 2020 | In Message and toBundle of Notification.java, there is a possible resource exhaustion due to improper input validation. ... |
| CVE-2020-0439 | HIGH | 7.8 | 0.2% | Nov 10, 2020 | In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permiss... |
| CVE-2020-0438 | HIGH | 7.8 | 0.2% | Nov 10, 2020 | In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data... |
| CVE-2020-0418 | HIGH | 7.8 | 0.3% | Nov 10, 2020 | In getPermissionInfosForGroup of Utils.java, there is a logic error. This could lead to local escalation of privilege wi... |
| CVE-2020-0409 | HIGH | 7.8 | 0.2% | Nov 10, 2020 | In create of FileMap.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local e... |
| CVE-2020-27694 | HIGH | 8.8 | 7.3% | Nov 9, 2020 | Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 has updated a specific critical library that may ... |
| CVE-2020-27016 | HIGH | 8.8 | 1.9% | Nov 9, 2020 | Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a cross-site request forgery (CS... |
| CVE-2020-28373 | HIGH | 8.8 | 1.0% | Nov 9, 2020 | upnpd on certain NETGEAR devices allows remote (LAN) attackers to execute arbitrary code via a stack-based buffer overfl... |
| CVE-2020-4759 | HIGH | 7.8 | 2.0% | Nov 9, 2020 | IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute ... |
| CVE-2020-27977 | HIGH | 7.8 | 0.3% | Nov 9, 2020 | CapaSystems CapaInstaller before 6.0.101 does not properly assign, modify, or check privileges for an actor who attempts... |
| CVE-2020-23140 | HIGH | 8.1 | 1.0% | Nov 9, 2020 | Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user... |
| CVE-2020-14366 | HIGH | 7.5 | 1.4% | Nov 9, 2020 | A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible b... |
| CVE-2020-8268 | HIGH | 7.5 | 1.3% | Nov 9, 2020 | Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify metho... |
| CVE-2020-24400 | HIGH | 7.1 | 2.3% | Nov 9, 2020 | Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensiti... |
| CVE-2020-7764 | HIGH | 7.5 | 1.7% | Nov 8, 2020 | This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now