2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26822CRITICAL10SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o...
CVE-2020-26821CRITICAL10SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o...
CVE-2020-26820HIGH7.2SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administra...
CVE-2020-26819HIGH8.8SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user...
CVE-2020-26818HIGH8.8SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user...
CVE-2020-26817HIGH7.8SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sourc...
CVE-2020-26815HIGH8.6SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send...
CVE-2020-26814MEDIUM4.9SAP Process Integration (PGP Module - Business-to-Business Add On), version - 1.0, allows an attacker to read PGP Keys u...
CVE-2020-26811MEDIUM5.3SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to ...
CVE-2020-26810HIGH7.5SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to ...
CVE-2020-26809MEDIUM5.3SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission c...
CVE-2020-26808HIGH7.2SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 a...
CVE-2020-26807LOW3.3SAP ERP Client for E-Bilanz, version - 1.0, installation sets Incorrect default filesystem permissions are set in its in...
CVE-2020-25074CRITICAL9.8The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request...
CVE-2020-7766CRITICAL9.8This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr...
CVE-2020-28267HIGH7.5Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and m...
CVE-2020-13927CRITICAL9.8The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th...
CVE-2020-12485MEDIUM5.5The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which c...
CVE-2020-5388MEDIUM6.9Dell Inspiron 15 7579 2-in-1 BIOS versions prior to 1.31.0 contain an Improper SMM communication buffer verification vul...
CVE-2020-4760MEDIUM5.4IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...
CVE-2020-4704MEDIUM5.4IBM Content Navigator 3.0CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbit...
CVE-2020-4568MEDIUM5.5IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, and 4.0 stores user credentials in plain in clear text which can be read by...
CVE-2020-24384CRITICAL9.8A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution ...
CVE-2020-0454MEDIUM5.5In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission...
CVE-2020-0453MEDIUM5.5In updateNotification of BeamTransferManager.java, there is a possible permission bypass due to an unsafe PendingIntent....

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now