2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4755MEDIUM5.4IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2020-4749MEDIUM4.3IBM Spectrum Scale 5.0.0 through 5.0.5.2 does not set the secure attribute on authorization tokens or session cookies. A...
CVE-2020-4748MEDIUM6.1IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2020-4564MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3...
CVE-2020-4491MEDIUM5.5IBM Spectrum Scale V4.2.0.0 through V4.2.3.22 and V5.0.0.0 through V5.0.5 could allow a local attacker to cause a denial...
CVE-2020-16246MEDIUM6.1The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow attackers to trick ...
CVE-2020-6370MEDIUM4.8SAP NetWeaver Design Time Repository (DTR), versions - 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-c...
CVE-2020-6369MEDIUM5.9SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an una...
CVE-2020-6367MEDIUM6.1There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.2...
CVE-2020-6366MEDIUM6.5SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents...
CVE-2020-6362MEDIUM6.5SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected re...
CVE-2020-6315MEDIUM5.5SAP 3D Visual Enterprise Viewer, version 9, allows an attacker to send certain manipulated file to the victim, which can...
CVE-2020-6308MEDIUM5.3SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated at...
CVE-2020-7749HIGH7.6This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template w...
CVE-2020-7748HIGH8.1This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used a...
CVE-2020-7747MEDIUM6.3This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a s...
CVE-2020-5640CRITICAL9.8Local file inclusion vulnerability in OneThird CMS v1.96c and earlier allows a remote unauthenticated attacker to execut...
CVE-2020-15261MEDIUM6.7On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally auth...
CVE-2020-15256CRITICAL9.8A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerab...
CVE-2020-6085HIGH7.5An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Br...
CVE-2020-6084HIGH7.5An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Br...
CVE-2020-15263MEDIUM6.1In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not e...
CVE-2020-15245MEDIUM4.3In Sylius before versions 1.6.9, 1.7.9 and 1.8.3, the user may register in a shop by email mail@example.com, verify it, ...
CVE-2020-13937MEDIUM5.3Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2....
CVE-2020-10746MEDIUM6.1A flaw was found in Infinispan (org.infinispan:infinispan-server-runtime) version 10, where it permits local access to c...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now