2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6273 | MEDIUM | 4.3 | 0.6% | Aug 12, 2020 | SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization check... |
| CVE-2020-2237 | MEDIUM | 4.3 | 0.7% | Aug 12, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Flaky Test Handler Plugin 1.0.4 and earlier allows attacker... |
| CVE-2020-2236 | MEDIUM | 5.4 | 0.7% | Aug 12, 2020 | Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cros... |
| CVE-2020-2235 | MEDIUM | 6.5 | 0.9% | Aug 12, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows ... |
| CVE-2020-2234 | MEDIUM | 6.5 | 1.1% | Aug 12, 2020 | A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read... |
| CVE-2020-2233 | MEDIUM | 6.5 | 0.8% | Aug 12, 2020 | A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read... |
| CVE-2020-2231 | MEDIUM | 5.4 | 5.3% | Aug 12, 2020 | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via '... |
| CVE-2020-2230 | MEDIUM | 5.4 | 83.1% | Aug 12, 2020 | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in... |
| CVE-2020-2229 | MEDIUM | 5.4 | 6.8% | Aug 12, 2020 | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a sto... |
| CVE-2020-13278 | MEDIUM | 6.1 | 1.4% | Aug 12, 2020 | Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remo... |
| CVE-2020-17373 | MEDIUM | 5.3 | 1.4% | Aug 12, 2020 | SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection. |
| CVE-2020-17372 | MEDIUM | 5.4 | 0.8% | Aug 12, 2020 | SugarCRM before 10.1.0 (Q3 2020) allows XSS. |
| CVE-2020-16266 | MEDIUM | 5.4 | 1.2% | Aug 12, 2020 | An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attack... |
| CVE-2020-16145 | MEDIUM | 6.1 | 1.9% | Aug 12, 2020 | Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG do... |
| CVE-2020-17489 | MEDIUM | 4.3 | 0.6% | Aug 11, 2020 | An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, t... |
| CVE-2020-8911 | MEDIUM | 5.6 | 0.3% | Aug 11, 2020 | A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to ... |
| CVE-2020-0258 | MEDIUM | 5.5 | 0.3% | Aug 11, 2020 | In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local information disclosure... |
| CVE-2020-0256 | MEDIUM | 6.8 | 0.2% | Aug 11, 2020 | In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This could lead ... |
| CVE-2020-0250 | MEDIUM | 5.5 | 0.1% | Aug 11, 2020 | In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to ... |
| CVE-2020-0249 | MEDIUM | 5.5 | 0.2% | Aug 11, 2020 | In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. T... |
| CVE-2020-0248 | MEDIUM | 5.5 | 0.2% | Aug 11, 2020 | In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. T... |
| CVE-2020-0247 | MEDIUM | 5.5 | 0.1% | Aug 11, 2020 | In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an uncaught exception. This... |
| CVE-2020-0239 | MEDIUM | 5.5 | 0.2% | Aug 11, 2020 | In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to... |
| CVE-2020-9403 | MEDIUM | 5.5 | 0.3% | Aug 11, 2020 | In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in a recoverable format, and may be retrieved b... |
| CVE-2020-9244 | MEDIUM | 6.8 | 0.2% | Aug 11, 2020 | HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now