2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-7273MEDIUM5.5Accessing functionality not properly constrained by ACLs vulnerability in the autorun start-up protection in McAfee Endp...
CVE-2020-7261MEDIUM5.5Buffer Overflow via Environment Variables vulnerability in AMSI component in McAfee Endpoint Security (ENS) Prior to 10....
CVE-2020-7257MEDIUM6.3Privilege escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update al...
CVE-2020-7278MEDIUM6.5Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Securi...
CVE-2020-10513MEDIUM6.5The file management interface of iCatch DVR firmware before 20200103 contains broken access control which allows the att...
CVE-2020-11765MEDIUM5.5An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by Dw...
CVE-2020-11764MEDIUM5.5An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.
CVE-2020-11763MEDIUM5.5An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated b...
CVE-2020-11762MEDIUM5.5An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress i...
CVE-2020-11761MEDIUM5.5An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonst...
CVE-2020-11760MEDIUM5.5An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompres...
CVE-2020-11759MEDIUM5.5An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeep...
CVE-2020-11758MEDIUM5.5An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.
CVE-2020-11005MEDIUM5.5The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vul...
CVE-2020-11001MEDIUM6.8In Wagtail before versions 2.8.1 and 2.7.2, a cross-site scripting (XSS) vulnerability exists on the page revision compa...
CVE-2020-8324MEDIUM5.5A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1....
CVE-2020-8316MEDIUM4.4A vulnerability was reported in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to r...
CVE-2020-7575MEDIUM6.1A vulnerability has been identified in Climatix POL908 (BACnet/IP module) (All versions), Climatix POL909 (AWM module) (...
CVE-2020-7574MEDIUM6.1A vulnerability has been identified in Climatix POL908 (BACnet/IP module) (All versions), Climatix POL909 (AWM module) (...
CVE-2020-6217MEDIUM6.1SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752,...
CVE-2020-6215MEDIUM6.1SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752,...
CVE-2020-6211MEDIUM6.1SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect user...
CVE-2020-11723MEDIUM5.5Cellebrite UFED 5.0 through 7.29 uses four hardcoded RSA private keys to authenticate to the ADB daemon on target device...
CVE-2020-6233MEDIUM4.3SAP S/4 HANA (Financial Products Subledger and Banking Services), versions - FSAPPL 400, 450, 500 and S4FPSL 100, allows...
CVE-2020-6232MEDIUM5.3SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now