2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-16593 | MEDIUM | 5.5 | 1.2% | Dec 9, 2020 | A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed... |
| CVE-2020-16592 | MEDIUM | 5.5 | 1.0% | Dec 9, 2020 | A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_... |
| CVE-2020-16591 | MEDIUM | 5.5 | 0.9% | Dec 9, 2020 | A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read... |
| CVE-2020-16590 | MEDIUM | 5.5 | 0.9% | Dec 9, 2020 | A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_... |
| CVE-2020-16589 | MEDIUM | 5.5 | 1.1% | Dec 9, 2020 | A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile.... |
| CVE-2020-16588 | MEDIUM | 5.5 | 1.2% | Dec 9, 2020 | A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp... |
| CVE-2020-16587 | MEDIUM | 5.5 | 1.2% | Dec 9, 2020 | A heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruct... |
| CVE-2020-28086 | HIGH | 7.5 | 0.6% | Dec 9, 2020 | pass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user... |
| CVE-2020-26257 | MEDIUM | 6.5 | 2.4% | Dec 9, 2020 | Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation... |
| CVE-2020-2049 | HIGH | 7.8 | 0.3% | Dec 9, 2020 | A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that al... |
| CVE-2020-2020 | MEDIUM | 5.5 | 0.3% | Dec 9, 2020 | An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows us... |
| CVE-2020-7787 | HIGH | 8.2 | 1.3% | Dec 9, 2020 | This affects all versions of package react-adal. It is possible for a specially crafted JWT token and request URL can ca... |
| CVE-2020-7776 | MEDIUM | 6.4 | 1.3% | Dec 9, 2020 | This affects the package phpoffice/phpspreadsheet from 0.0.0. The library is vulnerable to XSS when creating an html out... |
| CVE-2020-29661 | HIGH | 7.8 | 1.1% | Dec 9, 2020 | A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows... |
| CVE-2020-29660 | MEDIUM | 4.4 | 0.5% | Dec 9, 2020 | A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io... |
| CVE-2020-29659 | CRITICAL | 9.8 | 5.1% | Dec 9, 2020 | A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execut... |
| CVE-2020-26838 | CRITICAL | 9.1 | 2.2% | Dec 9, 2020 | SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions... |
| CVE-2020-26837 | CRITICAL | 9.1 | 1.9% | Dec 9, 2020 | SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious... |
| CVE-2020-26836 | MEDIUM | 6.1 | 2.3% | Dec 9, 2020 | SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to... |
| CVE-2020-26835 | MEDIUM | 6.1 | 0.8% | Dec 9, 2020 | SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attack... |
| CVE-2020-26834 | MEDIUM | 5.4 | 0.7% | Dec 9, 2020 | SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user ... |
| CVE-2020-26832 | HIGH | 7.6 | 2.2% | Dec 9, 2020 | SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_... |
| CVE-2020-26831 | CRITICAL | 9.6 | 1.1% | Dec 9, 2020 | SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML ... |
| CVE-2020-26830 | HIGH | 8.1 | 1.4% | Dec 9, 2020 | SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks fo... |
| CVE-2020-26829 | CRITICAL | 10 | 4.7% | Dec 9, 2020 | SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary conne... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now