2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-0005MEDIUM6.7In btm_read_remote_ext_features_complete of btm_acl.cc, there is a possible out of bounds write due to a missing bounds ...
CVE-2020-7208MEDIUM6.1LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is resolved in release 6.0-2.
CVE-2020-6973MEDIUM6.2Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2. Multiple cr...
CVE-2020-5241MEDIUM5.4matestack-ui-core (RubyGem) before 0.7.4 is vulnerable to XSS/Script injection. This vulnerability is patched in version...
CVE-2020-6975MEDIUM4.9Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2. Successful ...
CVE-2020-1976MEDIUM5.5A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authentica...
CVE-2020-6193MEDIUM6.1SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to...
CVE-2020-6190MEDIUM5.8Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide ...
CVE-2020-6189MEDIUM5.3Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error mess...
CVE-2020-6187MEDIUM4.9SAP NetWeaver (Guided Procedures), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an ...
CVE-2020-6185MEDIUM5.4Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS vers...
CVE-2020-6184MEDIUM6.1Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS ver...
CVE-2020-6183MEDIUM6.5SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sen...
CVE-2020-6181MEDIUM5.8Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP...
CVE-2020-6177MEDIUM4.3SAP Mobile Platform, version 3.0, does not sufficiently validate an XML document accepted from an untrusted source which...
CVE-2020-7957MEDIUM5.3The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be r...
CVE-2020-8839MEDIUM6.1Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cg...
CVE-2020-2133MEDIUM6.5Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master wher...
CVE-2020-2132MEDIUM6.5Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on th...
CVE-2020-2131MEDIUM6.5Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master ...
CVE-2020-2130MEDIUM6.5Jenkins Harvest SCM Plugin 0.5.1 and earlier stores a password unencrypted in its global configuration file on the Jenki...
CVE-2020-2129MEDIUM6.5Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenk...
CVE-2020-2128MEDIUM4.3Jenkins ECX Copy Data Management Plugin 1.9 and earlier stores a password unencrypted in job config.xml files on the Jen...
CVE-2020-2127MEDIUM4.3Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configura...
CVE-2020-2126MEDIUM4.3Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins mast...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now