2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-16593MEDIUM5.5A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed...
CVE-2020-16592MEDIUM5.5A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_...
CVE-2020-16591MEDIUM5.5A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read...
CVE-2020-16590MEDIUM5.5A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_...
CVE-2020-16589MEDIUM5.5A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile....
CVE-2020-16588MEDIUM5.5A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp...
CVE-2020-16587MEDIUM5.5A heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruct...
CVE-2020-28086HIGH7.5pass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user...
CVE-2020-26257MEDIUM6.5Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation...
CVE-2020-2049HIGH7.8A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that al...
CVE-2020-2020MEDIUM5.5An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows us...
CVE-2020-7787HIGH8.2This affects all versions of package react-adal. It is possible for a specially crafted JWT token and request URL can ca...
CVE-2020-7776MEDIUM6.4This affects the package phpoffice/phpspreadsheet from 0.0.0. The library is vulnerable to XSS when creating an html out...
CVE-2020-29661HIGH7.8A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows...
CVE-2020-29660MEDIUM4.4A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io...
CVE-2020-29659CRITICAL9.8A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execut...
CVE-2020-26838CRITICAL9.1SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions...
CVE-2020-26837CRITICAL9.1SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious...
CVE-2020-26836MEDIUM6.1SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to...
CVE-2020-26835MEDIUM6.1SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attack...
CVE-2020-26834MEDIUM5.4SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user ...
CVE-2020-26832HIGH7.6SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_...
CVE-2020-26831CRITICAL9.6SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML ...
CVE-2020-26830HIGH8.1SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks fo...
CVE-2020-26829CRITICAL10SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary conne...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now