2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-2003MEDIUM6.5An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator ...
CVE-2020-1997MEDIUM6.1An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to spec...
CVE-2020-1996MEDIUM5.3A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthentica...
CVE-2020-1995MEDIUM4.9A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a re...
CVE-2020-1994MEDIUM4.4A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell access to corrupt arbi...
CVE-2020-1993MEDIUM5.4The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which al...
CVE-2020-11070MEDIUM5.4The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invali...
CVE-2020-12831MEDIUM5.3An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, th...
CVE-2020-9501MEDIUM5.5Attackers can obtain Cloud Key information from the Dahua Web P2P control in specific ways. Cloud Key is used to authent...
CVE-2020-7455MEDIUM5.5In FreeBSD 12.1-STABLE before r360973, 12.1-RELEASE before p5, 11.4-STABLE before r360973, 11.4-BETA1 before p1 and 11.3...
CVE-2020-5838MEDIUM4.8Symantec IT Analytics, prior to 2.9.1, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of is...
CVE-2020-8020MEDIUM6.1A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attacker...
CVE-2020-4312MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 trough 6.0.3.1 could allow an authenticated user to obtain sensitiv...
CVE-2020-12742MEDIUM6.1The iubenda-cookie-law-solution plugin before 2.3.5 for WordPress does not restrict URL sanitization to http protocols.
CVE-2020-12700MEDIUM4.3The direct_mail extension through 5.2.3 for TYPO3 allows Information Disclosure via a newsletter subscriber data Special...
CVE-2020-12699MEDIUM6.1The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.
CVE-2020-12698MEDIUM4.3The direct_mail extension through 5.2.3 for TYPO3 has Broken Access Control for newsletter subscriber tables.
CVE-2020-12697MEDIUM5.3The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log entries.
CVE-2020-11062MEDIUM5.4In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type...
CVE-2020-12826MEDIUM5.3A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in ...
CVE-2020-6259MEDIUM6.5Under certain conditions SAP Adaptive Server Enterprise, versions 15.7, 16.0, allows an attacker to access information w...
CVE-2020-6258MEDIUM6.5SAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowin...
CVE-2020-6257MEDIUM5.4SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) 4.2 does not sufficiently encode user-control...
CVE-2020-6256MEDIUM4.3SAP Master Data Governance, versions - 748, 749, 750, 751, 752, 800, 801, 802, 803, 804, allows users to display change ...
CVE-2020-6254MEDIUM6.1SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors,...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now