2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-6273MEDIUM4.3SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization check...
CVE-2020-2237MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Flaky Test Handler Plugin 1.0.4 and earlier allows attacker...
CVE-2020-2236MEDIUM5.4Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cros...
CVE-2020-2235MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows ...
CVE-2020-2234MEDIUM6.5A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read...
CVE-2020-2233MEDIUM6.5A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read...
CVE-2020-2231MEDIUM5.4Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via '...
CVE-2020-2230MEDIUM5.4Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in...
CVE-2020-2229MEDIUM5.4Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a sto...
CVE-2020-13278MEDIUM6.1Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remo...
CVE-2020-17373MEDIUM5.3SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection.
CVE-2020-17372MEDIUM5.4SugarCRM before 10.1.0 (Q3 2020) allows XSS.
CVE-2020-16266MEDIUM5.4An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attack...
CVE-2020-16145MEDIUM6.1Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG do...
CVE-2020-17489MEDIUM4.3An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, t...
CVE-2020-8911MEDIUM5.6A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to ...
CVE-2020-0258MEDIUM5.5In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local information disclosure...
CVE-2020-0256MEDIUM6.8In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This could lead ...
CVE-2020-0250MEDIUM5.5In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to ...
CVE-2020-0249MEDIUM5.5In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. T...
CVE-2020-0248MEDIUM5.5In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. T...
CVE-2020-0247MEDIUM5.5In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an uncaught exception. This...
CVE-2020-0239MEDIUM5.5In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to...
CVE-2020-9403MEDIUM5.5In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in a recoverable format, and may be retrieved b...
CVE-2020-9244MEDIUM6.8HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now