2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15868 | HIGH | 7.5 | 1.1% | Aug 12, 2020 | Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control. |
| CVE-2020-16139 | HIGH | 7.5 | 79.8% | Aug 12, 2020 | A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the de... |
| CVE-2020-16138 | HIGH | 7.5 | 21.4% | Aug 12, 2020 | A denial-of-service issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to remot... |
| CVE-2020-7374 | HIGH | 7.8 | 3.1% | Aug 12, 2020 | Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validat... |
| CVE-2020-17360 | HIGH | 7.8 | 1.2% | Aug 12, 2020 | An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h contains multip... |
| CVE-2020-17505 | HIGH | 8.8 | 82.2% | Aug 12, 2020 | Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter i... |
| CVE-2020-17497 | HIGH | 8.1 | 0.7% | Aug 12, 2020 | eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAP... |
| CVE-2020-12674 | HIGH | 7.5 | 6.2% | Aug 12, 2020 | In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of ze... |
| CVE-2020-12673 | HIGH | 7.5 | 6.2% | Aug 12, 2020 | In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-... |
| CVE-2020-12100 | HIGH | 7.5 | 5.2% | Aug 12, 2020 | In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denia... |
| CVE-2020-13291 | HIGH | 8.1 | 1.0% | Aug 12, 2020 | In GitLab before 13.2.3, project sharing could temporarily allow too permissive access. |
| CVE-2020-13290 | HIGH | 7.2 | 1.1% | Aug 12, 2020 | In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page |
| CVE-2020-6309 | HIGH | 7.5 | 1.8% | Aug 12, 2020 | SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11),... |
| CVE-2020-6301 | HIGH | 8.1 | 0.7% | Aug 12, 2020 | SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthor... |
| CVE-2020-6298 | HIGH | 8.1 | 1.0% | Aug 12, 2020 | SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected B... |
| CVE-2020-6296 | HIGH | 8.8 | 1.3% | Aug 12, 2020 | SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, al... |
| CVE-2020-6295 | HIGH | 7.8 | 0.3% | Aug 12, 2020 | Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensit... |
| CVE-2020-2232 | HIGH | 7.5 | 0.8% | Aug 12, 2020 | Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the globa... |
| CVE-2020-8913 | HIGH | 8.8 | 2.9% | Aug 12, 2020 | A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Librar... |
| CVE-2020-7029 | HIGH | 8.8 | 0.4% | Aug 11, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Ava... |
| CVE-2020-17495 | HIGH | 7.5 | 0.9% | Aug 11, 2020 | django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables pass... |
| CVE-2020-17487 | HIGH | 7.5 | 1.8% | Aug 11, 2020 | radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentif... |
| CVE-2020-16170 | HIGH | 7.5 | 1.9% | Aug 11, 2020 | Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to ... |
| CVE-2020-0259 | HIGH | 7.8 | 0.2% | Aug 11, 2020 | In android_verity_ctr of dm-android-verity.c, there is a possible way to modify a dm-verity protected filesystem due to ... |
| CVE-2020-0257 | HIGH | 7.8 | 0.2% | Aug 11, 2020 | In SpecializeCommon of com_android_internal_os_Zygote.cpp, there is a permissions bypass due to an incomplete cleanup. T... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now