2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-1367MEDIUM5.5An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window...
CVE-2020-1361MEDIUM5.5An information disclosure vulnerability exists in the way that the WalletService handles memory.To exploit the vulnerabi...
CVE-2020-1358MEDIUM5.5An information disclosure vulnerability exists when the Windows Resource Policy component improperly handles memory.To e...
CVE-2020-1351MEDIUM5.5An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory,...
CVE-2020-1342MEDIUM5.5An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninit...
CVE-2020-1333MEDIUM6.7An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse po...
CVE-2020-1330MEDIUM5.5An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handle...
CVE-2020-1326MEDIUM5.4A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided inpu...
CVE-2020-1267MEDIUM4.9This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when ...
CVE-2020-15104MEDIUM5.4In Envoy before versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0 when validating TLS certificates, Envoy would incorrectly al...
CVE-2020-11084MEDIUM5.4In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manuall...
CVE-2020-5246MEDIUM6.5Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being us...
CVE-2020-11083MEDIUM4.8In October from version 1.0.319 and before version 1.0.466, a user with access to a markdown FormWidget that stores data...
CVE-2020-15721MEDIUM6.1RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.p...
CVE-2020-7592MEDIUM6.5A vulnerability has been identified in SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants) (All versions), S...
CVE-2020-7588MEDIUM5.3A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation ...
CVE-2020-7581MEDIUM6.7A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation ...
CVE-2020-7576MEDIUM5.4A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions...
CVE-2020-15720MEDIUM6.8In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. ...
CVE-2020-15719MEDIUM4.2libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asser...
CVE-2020-10043MEDIUM6.1A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions...
CVE-2020-10041MEDIUM6.1A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions...
CVE-2020-10040MEDIUM5.5A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions...
CVE-2020-6290MEDIUM6.3SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user ...
CVE-2020-6286MEDIUM5.3The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuratio...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now