2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6285 | MEDIUM | 6.5 | 1.1% | Jul 14, 2020 | SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain con... |
| CVE-2020-6282 | MEDIUM | 5.8 | 1.1% | Jul 14, 2020 | SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver ... |
| CVE-2020-6281 | MEDIUM | 6.1 | 0.8% | Jul 14, 2020 | SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-contr... |
| CVE-2020-6278 | MEDIUM | 5.4 | 0.5% | Jul 14, 2020 | SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to ... |
| CVE-2020-6276 | MEDIUM | 6.1 | 0.7% | Jul 14, 2020 | SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlle... |
| CVE-2020-6267 | MEDIUM | 5.4 | 0.8% | Jul 14, 2020 | Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cooki... |
| CVE-2020-4513 | MEDIUM | 6.1 | 0.7% | Jul 14, 2020 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2020-4511 | MEDIUM | 6.5 | 1.1% | Jul 14, 2020 | IBM QRadar SIEM 7.3 and 7.4 could allow an authenticated user to cause a denial of service of the qflow process by sendi... |
| CVE-2020-4510 | MEDIUM | 5.5 | 2.0% | Jul 14, 2020 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r... |
| CVE-2020-4364 | MEDIUM | 5.4 | 0.6% | Jul 14, 2020 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2020-11952 | MEDIUM | 6.2 | 0.5% | Jul 14, 2020 | An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. Attackers... |
| CVE-2020-10989 | MEDIUM | 6.1 | 0.9% | Jul 13, 2020 | An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to ex... |
| CVE-2020-10986 | MEDIUM | 6.5 | 0.6% | Jul 13, 2020 | A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to r... |
| CVE-2020-14174 | MEDIUM | 4.3 | 1.2% | Jul 13, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project vi... |
| CVE-2020-15105 | MEDIUM | 5.4 | 0.6% | Jul 10, 2020 | Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encod... |
| CVE-2020-4042 | MEDIUM | 6.8 | 1.0% | Jul 10, 2020 | Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of... |
| CVE-2020-8198 | MEDIUM | 6.1 | 1.0% | Jul 10, 2020 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.1... |
| CVE-2020-8196 | MEDIUM | 4.3 | 26.3% | Jul 10, 2020 | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 ... |
| CVE-2020-8195 | MEDIUM | 6.5 | 33.3% | Jul 10, 2020 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.1... |
| CVE-2020-8194 | MEDIUM | 6.5 | 10.7% | Jul 10, 2020 | Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14... |
| CVE-2020-8193 | MEDIUM | 6.5 | 88.4% | Jul 10, 2020 | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 ... |
| CVE-2020-8191 | MEDIUM | 6.1 | 22.9% | Jul 10, 2020 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.1... |
| CVE-2020-8181 | MEDIUM | 4.3 | 0.8% | Jul 10, 2020 | A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars. |
| CVE-2020-9260 | MEDIUM | 6.5 | 0.3% | Jul 10, 2020 | HUAWEI P30 and HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E22R2P5) and versions earlier than 1... |
| CVE-2020-9258 | MEDIUM | 5.5 | 0.2% | Jul 10, 2020 | HUAWEI P30 smartphone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper input verification vulnerabil... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now