2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-12427HIGH8.8The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF,...
CVE-2020-3341HIGH7.5A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could all...
CVE-2020-3327HIGH7.5A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an un...
CVE-2020-1718HIGH8.8A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gai...
CVE-2020-11057HIGH8.8In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute py...
CVE-2020-12772HIGH8.8An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can inclu...
CVE-2020-11060HIGH8.8In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this v...
CVE-2020-6262HIGH8.8Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_...
CVE-2020-6253HIGH7.2Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated us...
CVE-2020-6252HIGH8Under certain conditions SAP Adaptive Server Enterprise (Cockpit), version 16.0, allows an attacker with access to local...
CVE-2020-6249HIGH8.8The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS...
CVE-2020-6248HIGH7.2SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an au...
CVE-2020-6247HIGH7.5SAP Business Objects Business Intelligence Platform, version 4.2, allows an unauthenticated attacker to prevent legitima...
CVE-2020-6244HIGH7.8SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious co...
CVE-2020-6243HIGH8.8Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not ...
CVE-2020-6241HIGH8.8SAP Adaptive Server Enterprise, version 16.0, allows an authenticated user to execute crafted database queries to elevat...
CVE-2020-6240HIGH7.5SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allo...
CVE-2020-12825HIGH7.1libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption...
CVE-2020-5897HIGH8.8In versions 7.1.5-7.1.9, there is use-after-free memory vulnerability in the BIG-IP Edge Client Windows ActiveX componen...
CVE-2020-5896HIGH7.8On versions 7.1.5-7.1.9, the BIG-IP Edge Client's Windows Installer Service's temporary folder has weak file and folder ...
CVE-2020-1763HIGH7.5An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unau...
CVE-2020-8156HIGH7A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
CVE-2020-8154HIGH7.7An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices ...
CVE-2020-8153HIGH8.1Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible ...
CVE-2020-8151HIGH7.5There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create speci...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now