2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2003 | MEDIUM | 6.5 | 0.9% | May 13, 2020 | An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator ... |
| CVE-2020-1997 | MEDIUM | 6.1 | 0.9% | May 13, 2020 | An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to spec... |
| CVE-2020-1996 | MEDIUM | 5.3 | 0.9% | May 13, 2020 | A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthentica... |
| CVE-2020-1995 | MEDIUM | 4.9 | 1.1% | May 13, 2020 | A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a re... |
| CVE-2020-1994 | MEDIUM | 4.4 | 0.2% | May 13, 2020 | A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell access to corrupt arbi... |
| CVE-2020-1993 | MEDIUM | 5.4 | 0.4% | May 13, 2020 | The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which al... |
| CVE-2020-11070 | MEDIUM | 5.4 | 0.5% | May 13, 2020 | The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invali... |
| CVE-2020-12831 | MEDIUM | 5.3 | 1.4% | May 13, 2020 | An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, th... |
| CVE-2020-9501 | MEDIUM | 5.5 | 0.3% | May 13, 2020 | Attackers can obtain Cloud Key information from the Dahua Web P2P control in specific ways. Cloud Key is used to authent... |
| CVE-2020-7455 | MEDIUM | 5.5 | 0.5% | May 13, 2020 | In FreeBSD 12.1-STABLE before r360973, 12.1-RELEASE before p5, 11.4-STABLE before r360973, 11.4-BETA1 before p1 and 11.3... |
| CVE-2020-5838 | MEDIUM | 4.8 | 0.7% | May 13, 2020 | Symantec IT Analytics, prior to 2.9.1, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of is... |
| CVE-2020-8020 | MEDIUM | 6.1 | 0.9% | May 13, 2020 | A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attacker... |
| CVE-2020-4312 | MEDIUM | 4.3 | 0.8% | May 13, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 trough 6.0.3.1 could allow an authenticated user to obtain sensitiv... |
| CVE-2020-12742 | MEDIUM | 6.1 | 1.1% | May 13, 2020 | The iubenda-cookie-law-solution plugin before 2.3.5 for WordPress does not restrict URL sanitization to http protocols. |
| CVE-2020-12700 | MEDIUM | 4.3 | 0.8% | May 13, 2020 | The direct_mail extension through 5.2.3 for TYPO3 allows Information Disclosure via a newsletter subscriber data Special... |
| CVE-2020-12699 | MEDIUM | 6.1 | 0.8% | May 13, 2020 | The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl. |
| CVE-2020-12698 | MEDIUM | 4.3 | 0.8% | May 13, 2020 | The direct_mail extension through 5.2.3 for TYPO3 has Broken Access Control for newsletter subscriber tables. |
| CVE-2020-12697 | MEDIUM | 5.3 | 1.3% | May 13, 2020 | The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log entries. |
| CVE-2020-11062 | MEDIUM | 5.4 | 0.5% | May 12, 2020 | In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type... |
| CVE-2020-12826 | MEDIUM | 5.3 | 0.7% | May 12, 2020 | A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in ... |
| CVE-2020-6259 | MEDIUM | 6.5 | 0.8% | May 12, 2020 | Under certain conditions SAP Adaptive Server Enterprise, versions 15.7, 16.0, allows an attacker to access information w... |
| CVE-2020-6258 | MEDIUM | 6.5 | 0.7% | May 12, 2020 | SAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowin... |
| CVE-2020-6257 | MEDIUM | 5.4 | 0.5% | May 12, 2020 | SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) 4.2 does not sufficiently encode user-control... |
| CVE-2020-6256 | MEDIUM | 4.3 | 0.6% | May 12, 2020 | SAP Master Data Governance, versions - 748, 749, 750, 751, 752, 800, 801, 802, 803, 804, allows users to display change ... |
| CVE-2020-6254 | MEDIUM | 6.1 | 0.7% | May 12, 2020 | SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors,... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now