2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26822 | CRITICAL | 10 | 1.3% | Nov 10, 2020 | SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o... |
| CVE-2020-26821 | CRITICAL | 10 | 1.3% | Nov 10, 2020 | SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o... |
| CVE-2020-26820 | HIGH | 7.2 | 3.9% | Nov 10, 2020 | SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administra... |
| CVE-2020-26819 | HIGH | 8.8 | 0.9% | Nov 10, 2020 | SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user... |
| CVE-2020-26818 | HIGH | 8.8 | 1.1% | Nov 10, 2020 | SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user... |
| CVE-2020-26817 | HIGH | 7.8 | 1.2% | Nov 10, 2020 | SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sourc... |
| CVE-2020-26815 | HIGH | 8.6 | 1.4% | Nov 10, 2020 | SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send... |
| CVE-2020-26814 | MEDIUM | 4.9 | 0.9% | Nov 10, 2020 | SAP Process Integration (PGP Module - Business-to-Business Add On), version - 1.0, allows an attacker to read PGP Keys u... |
| CVE-2020-26811 | MEDIUM | 5.3 | 1.8% | Nov 10, 2020 | SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to ... |
| CVE-2020-26810 | HIGH | 7.5 | 1.1% | Nov 10, 2020 | SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to ... |
| CVE-2020-26809 | MEDIUM | 5.3 | 2.0% | Nov 10, 2020 | SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission c... |
| CVE-2020-26808 | HIGH | 7.2 | 3.0% | Nov 10, 2020 | SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 a... |
| CVE-2020-26807 | LOW | 3.3 | 0.3% | Nov 10, 2020 | SAP ERP Client for E-Bilanz, version - 1.0, installation sets Incorrect default filesystem permissions are set in its in... |
| CVE-2020-25074 | CRITICAL | 9.8 | 6.1% | Nov 10, 2020 | The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request... |
| CVE-2020-7766 | CRITICAL | 9.8 | 1.9% | Nov 10, 2020 | This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr... |
| CVE-2020-28267 | HIGH | 7.5 | 2.2% | Nov 10, 2020 | Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and m... |
| CVE-2020-13927 | CRITICAL | 9.8 | 99.7% | Nov 10, 2020 | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th... |
| CVE-2020-12485 | MEDIUM | 5.5 | 0.3% | Nov 10, 2020 | The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which c... |
| CVE-2020-5388 | MEDIUM | 6.9 | 0.3% | Nov 10, 2020 | Dell Inspiron 15 7579 2-in-1 BIOS versions prior to 1.31.0 contain an Improper SMM communication buffer verification vul... |
| CVE-2020-4760 | MEDIUM | 5.4 | 0.9% | Nov 10, 2020 | IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2020-4704 | MEDIUM | 5.4 | 0.9% | Nov 10, 2020 | IBM Content Navigator 3.0CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2020-4568 | MEDIUM | 5.5 | 0.7% | Nov 10, 2020 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, and 4.0 stores user credentials in plain in clear text which can be read by... |
| CVE-2020-24384 | CRITICAL | 9.8 | 3.4% | Nov 10, 2020 | A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution ... |
| CVE-2020-0454 | MEDIUM | 5.5 | 0.2% | Nov 10, 2020 | In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission... |
| CVE-2020-0453 | MEDIUM | 5.5 | 0.3% | Nov 10, 2020 | In updateNotification of BeamTransferManager.java, there is a possible permission bypass due to an unsafe PendingIntent.... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now