2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-6251MEDIUM6.5Under certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, version 4.2, allows an ...
CVE-2020-6250MEDIUM6.8SAP Adaptive Server Enterprise, version 16.0, allows an authenticated attacker to exploit certain misconfigured endpoint...
CVE-2020-6245MEDIUM6.7SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to i...
CVE-2020-1746MEDIUM5A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and...
CVE-2020-5898MEDIUM5.5In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the use...
CVE-2020-5248MEDIUM5.3GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used o...
CVE-2020-4346MEDIUM5.3IBM API Connect's V2018.4.1.0 through 2018.4.1.10 management server has an unsecured api which can be exploited by an un...
CVE-2020-4195MEDIUM5.4IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victi...
CVE-2020-10706MEDIUM6.6A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at res...
CVE-2020-8155MEDIUM5.4An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerab...
CVE-2020-10060MEDIUM6.5In updatehub_probe, right after JSON parsing is complete, objects\[1] is accessed from the output structure in two diffe...
CVE-2020-10059MEDIUM4.8The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firm...
CVE-2020-10023MEDIUM6.8The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause...
CVE-2020-1724MEDIUM4.3A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to...
CVE-2020-7647MEDIUM5.3All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby ...
CVE-2020-5834MEDIUM5.3Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow...
CVE-2020-12784MEDIUM5.3cPanel before 86.0.14 allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505).
CVE-2020-12748MEDIUM5.3An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protectio...
CVE-2020-11864MEDIUM5.5libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 2 of 2).
CVE-2020-11863MEDIUM5.5libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).
CVE-2020-1698MEDIUM5.5A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password ...
CVE-2020-10685MEDIUM5.5A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9...
CVE-2020-9314MEDIUM4.8** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration c...
CVE-2020-12771MEDIUM5.5An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadloc...
CVE-2020-12770MEDIUM6.7An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failur...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now