2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26811 | MEDIUM | 5.3 | 1.8% | Nov 10, 2020 | SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to ... |
| CVE-2020-26809 | MEDIUM | 5.3 | 2.0% | Nov 10, 2020 | SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission c... |
| CVE-2020-12485 | MEDIUM | 5.5 | 0.3% | Nov 10, 2020 | The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which c... |
| CVE-2020-5388 | MEDIUM | 6.9 | 0.3% | Nov 10, 2020 | Dell Inspiron 15 7579 2-in-1 BIOS versions prior to 1.31.0 contain an Improper SMM communication buffer verification vul... |
| CVE-2020-4760 | MEDIUM | 5.4 | 0.9% | Nov 10, 2020 | IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2020-4704 | MEDIUM | 5.4 | 0.9% | Nov 10, 2020 | IBM Content Navigator 3.0CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2020-4568 | MEDIUM | 5.5 | 0.7% | Nov 10, 2020 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, and 4.0 stores user credentials in plain in clear text which can be read by... |
| CVE-2020-0454 | MEDIUM | 5.5 | 0.2% | Nov 10, 2020 | In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission... |
| CVE-2020-0453 | MEDIUM | 5.5 | 0.3% | Nov 10, 2020 | In updateNotification of BeamTransferManager.java, there is a possible permission bypass due to an unsafe PendingIntent.... |
| CVE-2020-0450 | MEDIUM | 6.5 | 0.8% | Nov 10, 2020 | In rw_i93_sm_format of rw_i93.cc, there is a possible out of bounds read due to uninitialized data. This could lead to r... |
| CVE-2020-0448 | MEDIUM | 5.5 | 0.1% | Nov 10, 2020 | In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to... |
| CVE-2020-0443 | MEDIUM | 5.5 | 0.3% | Nov 10, 2020 | In LocaleList of LocaleList.java, there is a possible forced reboot due to an uncaught exception. This could lead to loc... |
| CVE-2020-0437 | MEDIUM | 5.5 | 0.1% | Nov 10, 2020 | In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. Thi... |
| CVE-2020-0424 | MEDIUM | 5.5 | 0.2% | Nov 10, 2020 | In send_vc of res_send.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to ... |
| CVE-2020-16125 | MEDIUM | 6.8 | 1.1% | Nov 10, 2020 | gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service v... |
| CVE-2020-27693 | MEDIUM | 4.4 | 1.8% | Nov 9, 2020 | Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 stores administrative passwords using a hash that... |
| CVE-2020-27019 | MEDIUM | 5.5 | 17.9% | Nov 9, 2020 | Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulner... |
| CVE-2020-27018 | MEDIUM | 5.5 | 3.5% | Nov 9, 2020 | Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vu... |
| CVE-2020-27017 | MEDIUM | 4.9 | 6.4% | Nov 9, 2020 | Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processin... |
| CVE-2020-4651 | MEDIUM | 4.8 | 0.3% | Nov 9, 2020 | IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 is vulnerable to cross-site request forgery w... |
| CVE-2020-28364 | MEDIUM | 6.1 | 0.6% | Nov 9, 2020 | A stored cross-site scripting (XSS) vulnerability affects the Web UI in Locust before 1.3.2, if the installation violate... |
| CVE-2020-23139 | MEDIUM | 5.5 | 0.3% | Nov 9, 2020 | Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which ... |
| CVE-2020-23136 | MEDIUM | 5.5 | 0.3% | Nov 9, 2020 | Microweber v1.1.18 is affected by no session expiry after log-out. |
| CVE-2020-9300 | MEDIUM | 6.5 | 0.9% | Nov 9, 2020 | The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, ... |
| CVE-2020-9299 | MEDIUM | 5.4 | 0.6% | Nov 9, 2020 | There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description param... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now