2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6251 | MEDIUM | 6.5 | 0.8% | May 12, 2020 | Under certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, version 4.2, allows an ... |
| CVE-2020-6250 | MEDIUM | 6.8 | 0.5% | May 12, 2020 | SAP Adaptive Server Enterprise, version 16.0, allows an authenticated attacker to exploit certain misconfigured endpoint... |
| CVE-2020-6245 | MEDIUM | 6.7 | 0.3% | May 12, 2020 | SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to i... |
| CVE-2020-1746 | MEDIUM | 5 | 0.4% | May 12, 2020 | A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and... |
| CVE-2020-5898 | MEDIUM | 5.5 | 0.3% | May 12, 2020 | In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the use... |
| CVE-2020-5248 | MEDIUM | 5.3 | 1.4% | May 12, 2020 | GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used o... |
| CVE-2020-4346 | MEDIUM | 5.3 | 1.1% | May 12, 2020 | IBM API Connect's V2018.4.1.0 through 2018.4.1.10 management server has an unsecured api which can be exploited by an un... |
| CVE-2020-4195 | MEDIUM | 5.4 | 0.6% | May 12, 2020 | IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victi... |
| CVE-2020-10706 | MEDIUM | 6.6 | 0.1% | May 12, 2020 | A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at res... |
| CVE-2020-8155 | MEDIUM | 5.4 | 1.1% | May 12, 2020 | An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerab... |
| CVE-2020-10060 | MEDIUM | 6.5 | 1.6% | May 11, 2020 | In updatehub_probe, right after JSON parsing is complete, objects\[1] is accessed from the output structure in two diffe... |
| CVE-2020-10059 | MEDIUM | 4.8 | 1.2% | May 11, 2020 | The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firm... |
| CVE-2020-10023 | MEDIUM | 6.8 | 0.5% | May 11, 2020 | The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause... |
| CVE-2020-1724 | MEDIUM | 4.3 | 0.8% | May 11, 2020 | A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to... |
| CVE-2020-7647 | MEDIUM | 5.3 | 1.6% | May 11, 2020 | All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby ... |
| CVE-2020-5834 | MEDIUM | 5.3 | 1.7% | May 11, 2020 | Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to a directory traversal attack that could allow... |
| CVE-2020-12784 | MEDIUM | 5.3 | 1.3% | May 11, 2020 | cPanel before 86.0.14 allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505). |
| CVE-2020-12748 | MEDIUM | 5.3 | 0.3% | May 11, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protectio... |
| CVE-2020-11864 | MEDIUM | 5.5 | 1.2% | May 11, 2020 | libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 2 of 2). |
| CVE-2020-11863 | MEDIUM | 5.5 | 1.1% | May 11, 2020 | libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2). |
| CVE-2020-1698 | MEDIUM | 5.5 | 0.4% | May 11, 2020 | A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password ... |
| CVE-2020-10685 | MEDIUM | 5.5 | 0.4% | May 11, 2020 | A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9... |
| CVE-2020-9314 | MEDIUM | 4.8 | 1.3% | May 10, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration c... |
| CVE-2020-12771 | MEDIUM | 5.5 | 0.5% | May 9, 2020 | An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadloc... |
| CVE-2020-12770 | MEDIUM | 6.7 | 0.6% | May 9, 2020 | An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failur... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now