2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-15868HIGH7.5Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.
CVE-2020-16139HIGH7.5A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the de...
CVE-2020-16138HIGH7.5A denial-of-service issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to remot...
CVE-2020-7374HIGH7.8Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validat...
CVE-2020-17360HIGH7.8An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h contains multip...
CVE-2020-17505HIGH8.8Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter i...
CVE-2020-17497HIGH8.1eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAP...
CVE-2020-12674HIGH7.5In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of ze...
CVE-2020-12673HIGH7.5In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-...
CVE-2020-12100HIGH7.5In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denia...
CVE-2020-13291HIGH8.1In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.
CVE-2020-13290HIGH7.2In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page
CVE-2020-6309HIGH7.5SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11),...
CVE-2020-6301HIGH8.1SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthor...
CVE-2020-6298HIGH8.1SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected B...
CVE-2020-6296HIGH8.8SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, al...
CVE-2020-6295HIGH7.8Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensit...
CVE-2020-2232HIGH7.5Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the globa...
CVE-2020-8913HIGH8.8A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Librar...
CVE-2020-7029HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Ava...
CVE-2020-17495HIGH7.5django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables pass...
CVE-2020-17487HIGH7.5radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentif...
CVE-2020-16170HIGH7.5Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to ...
CVE-2020-0259HIGH7.8In android_verity_ctr of dm-android-verity.c, there is a possible way to modify a dm-verity protected filesystem due to ...
CVE-2020-0257HIGH7.8In SpecializeCommon of com_android_internal_os_Zygote.cpp, there is a permissions bypass due to an incomplete cleanup. T...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now