2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-8318HIGH7.8A privilege escalation vulnerability was reported in the LenovoSystemUpdatePlugin for Lenovo System Interface Foundation...
CVE-2020-9384HIGH8.8An Insecure Direct Object Reference (IDOR) vulnerability in the Change Password feature of Subex ROC Partner Settlement ...
CVE-2020-6225HIGH8.8SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31...
CVE-2020-6237HIGH7.5Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dswsbobje web applicati...
CVE-2020-6236HIGH7.2SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group pri...
CVE-2020-6235HIGH8.6SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities...
CVE-2020-6234HIGH7.2SAP Host Agent, version 7.21, allows an attacker with admin privileges to use the operation framework to gain root privi...
CVE-2020-6230HIGH7.2SAP OrientDB, version 3.0, allows an authenticated attacker with script execute/write permissions to inject code that ca...
CVE-2020-6228HIGH7.5SAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attac...
CVE-2020-6227HIGH7.5SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specia...
CVE-2020-6219HIGH8.8SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Repo...
CVE-2020-10384HIGH7.8An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.6.1. The...
CVE-2020-7800HIGH8.2The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Improper Check fo...
CVE-2020-10382HIGH8.8An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. The...
CVE-2020-9004HIGH8.8A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-on...
CVE-2020-5739HIGH8.8Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an ...
CVE-2020-5738HIGH8.8Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an ...
CVE-2020-11741HIGH8.8An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sen...
CVE-2020-11739HIGH7.8An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain pri...
CVE-2020-11738HIGH7.5The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver...
CVE-2020-10646HIGH7.8Fuji Electric V-Server Lite all versions prior to 4.0.9.0 contains a heap based buffer overflow. The buffer allocated to...
CVE-2020-10642HIGH7.8In Rockwell Automation RSLinx Classic versions 4.11.00 and prior, an authenticated local attacker could modify a registr...
CVE-2020-6455HIGH8.8Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit hea...
CVE-2020-6454HIGH8.8Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install ...
CVE-2020-6452HIGH8.8Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit h...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now