2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24416 | MEDIUM | 6.1 | 1.9% | Oct 20, 2020 | Marketo Sales Insight plugin version 1.4355 (and earlier) is affected by a blind stored Cross-Site Scripting (XSS) vulne... |
| CVE-2020-7371 | MEDIUM | 4.3 | 1.0% | Oct 20, 2020 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser all... |
| CVE-2020-7370 | MEDIUM | 4.3 | 1.0% | Oct 20, 2020 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of Danyil Vasilenko's Bol... |
| CVE-2020-7369 | MEDIUM | 4.3 | 1.0% | Oct 20, 2020 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser all... |
| CVE-2020-7364 | MEDIUM | 4.3 | 0.7% | Oct 20, 2020 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser all... |
| CVE-2020-7363 | MEDIUM | 4.3 | 0.7% | Oct 20, 2020 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser all... |
| CVE-2020-3995 | MEDIUM | 5.3 | 1.1% | Oct 20, 2020 | In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fus... |
| CVE-2020-3993 | MEDIUM | 5.9 | 0.9% | Oct 20, 2020 | VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allo... |
| CVE-2020-3981 | MEDIUM | 5.8 | 0.8% | Oct 20, 2020 | VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Work... |
| CVE-2020-4756 | MEDIUM | 5.5 | 0.3% | Oct 20, 2020 | IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 ... |
| CVE-2020-4755 | MEDIUM | 5.4 | 0.6% | Oct 20, 2020 | IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2020-4749 | MEDIUM | 4.3 | 1.0% | Oct 20, 2020 | IBM Spectrum Scale 5.0.0 through 5.0.5.2 does not set the secure attribute on authorization tokens or session cookies. A... |
| CVE-2020-4748 | MEDIUM | 6.1 | 0.7% | Oct 20, 2020 | IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2020-4564 | MEDIUM | 5.4 | 0.7% | Oct 20, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3... |
| CVE-2020-4491 | MEDIUM | 5.5 | 0.3% | Oct 20, 2020 | IBM Spectrum Scale V4.2.0.0 through V4.2.3.22 and V5.0.0.0 through V5.0.5 could allow a local attacker to cause a denial... |
| CVE-2020-16246 | MEDIUM | 6.1 | 0.7% | Oct 20, 2020 | The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow attackers to trick ... |
| CVE-2020-6370 | MEDIUM | 4.8 | 0.5% | Oct 20, 2020 | SAP NetWeaver Design Time Repository (DTR), versions - 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-c... |
| CVE-2020-6369 | MEDIUM | 5.9 | 2.6% | Oct 20, 2020 | SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an una... |
| CVE-2020-6367 | MEDIUM | 6.1 | 0.8% | Oct 20, 2020 | There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.2... |
| CVE-2020-6366 | MEDIUM | 6.5 | 1.1% | Oct 20, 2020 | SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents... |
| CVE-2020-6362 | MEDIUM | 6.5 | 1.0% | Oct 20, 2020 | SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected re... |
| CVE-2020-6315 | MEDIUM | 5.5 | 0.8% | Oct 20, 2020 | SAP 3D Visual Enterprise Viewer, version 9, allows an attacker to send certain manipulated file to the victim, which can... |
| CVE-2020-6308 | MEDIUM | 5.3 | 61.7% | Oct 20, 2020 | SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated at... |
| CVE-2020-7747 | MEDIUM | 6.3 | 0.9% | Oct 20, 2020 | This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a s... |
| CVE-2020-15261 | MEDIUM | 6.7 | 11.1% | Oct 19, 2020 | On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally auth... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now