2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12427 | HIGH | 8.8 | 0.5% | May 13, 2020 | The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF,... |
| CVE-2020-3341 | HIGH | 7.5 | 3.4% | May 13, 2020 | A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could all... |
| CVE-2020-3327 | HIGH | 7.5 | 5.1% | May 13, 2020 | A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an un... |
| CVE-2020-1718 | HIGH | 8.8 | 1.0% | May 12, 2020 | A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gai... |
| CVE-2020-11057 | HIGH | 8.8 | 2.2% | May 12, 2020 | In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute py... |
| CVE-2020-12772 | HIGH | 8.8 | 1.7% | May 12, 2020 | An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can inclu... |
| CVE-2020-11060 | HIGH | 8.8 | 10.9% | May 12, 2020 | In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this v... |
| CVE-2020-6262 | HIGH | 8.8 | 1.2% | May 12, 2020 | Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_... |
| CVE-2020-6253 | HIGH | 7.2 | 1.2% | May 12, 2020 | Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated us... |
| CVE-2020-6252 | HIGH | 8 | 0.5% | May 12, 2020 | Under certain conditions SAP Adaptive Server Enterprise (Cockpit), version 16.0, allows an attacker with access to local... |
| CVE-2020-6249 | HIGH | 8.8 | 1.0% | May 12, 2020 | The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS... |
| CVE-2020-6248 | HIGH | 7.2 | 1.9% | May 12, 2020 | SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an au... |
| CVE-2020-6247 | HIGH | 7.5 | 1.0% | May 12, 2020 | SAP Business Objects Business Intelligence Platform, version 4.2, allows an unauthenticated attacker to prevent legitima... |
| CVE-2020-6244 | HIGH | 7.8 | 0.3% | May 12, 2020 | SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious co... |
| CVE-2020-6243 | HIGH | 8.8 | 0.9% | May 12, 2020 | Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not ... |
| CVE-2020-6241 | HIGH | 8.8 | 1.0% | May 12, 2020 | SAP Adaptive Server Enterprise, version 16.0, allows an authenticated user to execute crafted database queries to elevat... |
| CVE-2020-6240 | HIGH | 7.5 | 1.4% | May 12, 2020 | SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allo... |
| CVE-2020-12825 | HIGH | 7.1 | 2.3% | May 12, 2020 | libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption... |
| CVE-2020-5897 | HIGH | 8.8 | 1.2% | May 12, 2020 | In versions 7.1.5-7.1.9, there is use-after-free memory vulnerability in the BIG-IP Edge Client Windows ActiveX componen... |
| CVE-2020-5896 | HIGH | 7.8 | 0.3% | May 12, 2020 | On versions 7.1.5-7.1.9, the BIG-IP Edge Client's Windows Installer Service's temporary folder has weak file and folder ... |
| CVE-2020-1763 | HIGH | 7.5 | 3.3% | May 12, 2020 | An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unau... |
| CVE-2020-8156 | HIGH | 7 | 0.9% | May 12, 2020 | A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack. |
| CVE-2020-8154 | HIGH | 7.7 | 1.8% | May 12, 2020 | An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices ... |
| CVE-2020-8153 | HIGH | 8.1 | 1.9% | May 12, 2020 | Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible ... |
| CVE-2020-8151 | HIGH | 7.5 | 2.2% | May 12, 2020 | There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create speci... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now