2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-6285MEDIUM6.5SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain con...
CVE-2020-6282MEDIUM5.8SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver ...
CVE-2020-6281MEDIUM6.1SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-contr...
CVE-2020-6278MEDIUM5.4SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to ...
CVE-2020-6276MEDIUM6.1SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlle...
CVE-2020-6267MEDIUM5.4Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cooki...
CVE-2020-4513MEDIUM6.1IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...
CVE-2020-4511MEDIUM6.5IBM QRadar SIEM 7.3 and 7.4 could allow an authenticated user to cause a denial of service of the qflow process by sendi...
CVE-2020-4510MEDIUM5.5IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r...
CVE-2020-4364MEDIUM5.4IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...
CVE-2020-11952MEDIUM6.2An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. Attackers...
CVE-2020-10989MEDIUM6.1An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to ex...
CVE-2020-10986MEDIUM6.5A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to r...
CVE-2020-14174MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project vi...
CVE-2020-15105MEDIUM5.4Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encod...
CVE-2020-4042MEDIUM6.8Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of...
CVE-2020-8198MEDIUM6.1Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.1...
CVE-2020-8196MEDIUM4.3Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 ...
CVE-2020-8195MEDIUM6.5Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.1...
CVE-2020-8194MEDIUM6.5Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14...
CVE-2020-8193MEDIUM6.5Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 ...
CVE-2020-8191MEDIUM6.1Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.1...
CVE-2020-8181MEDIUM4.3A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
CVE-2020-9260MEDIUM6.5HUAWEI P30 and HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E22R2P5) and versions earlier than 1...
CVE-2020-9258MEDIUM5.5HUAWEI P30 smartphone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper input verification vulnerabil...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now