2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4755 | MEDIUM | 5.4 | 0.6% | Oct 20, 2020 | IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2020-4749 | MEDIUM | 4.3 | 1.0% | Oct 20, 2020 | IBM Spectrum Scale 5.0.0 through 5.0.5.2 does not set the secure attribute on authorization tokens or session cookies. A... |
| CVE-2020-4748 | MEDIUM | 6.1 | 0.7% | Oct 20, 2020 | IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2020-4564 | MEDIUM | 5.4 | 0.7% | Oct 20, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3... |
| CVE-2020-4491 | MEDIUM | 5.5 | 0.3% | Oct 20, 2020 | IBM Spectrum Scale V4.2.0.0 through V4.2.3.22 and V5.0.0.0 through V5.0.5 could allow a local attacker to cause a denial... |
| CVE-2020-16246 | MEDIUM | 6.1 | 0.7% | Oct 20, 2020 | The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow attackers to trick ... |
| CVE-2020-6370 | MEDIUM | 4.8 | 0.5% | Oct 20, 2020 | SAP NetWeaver Design Time Repository (DTR), versions - 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-c... |
| CVE-2020-6369 | MEDIUM | 5.9 | 2.6% | Oct 20, 2020 | SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an una... |
| CVE-2020-6367 | MEDIUM | 6.1 | 0.8% | Oct 20, 2020 | There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.2... |
| CVE-2020-6366 | MEDIUM | 6.5 | 1.1% | Oct 20, 2020 | SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents... |
| CVE-2020-6362 | MEDIUM | 6.5 | 1.0% | Oct 20, 2020 | SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected re... |
| CVE-2020-6315 | MEDIUM | 5.5 | 0.8% | Oct 20, 2020 | SAP 3D Visual Enterprise Viewer, version 9, allows an attacker to send certain manipulated file to the victim, which can... |
| CVE-2020-6308 | MEDIUM | 5.3 | 61.7% | Oct 20, 2020 | SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated at... |
| CVE-2020-7749 | HIGH | 7.6 | 1.6% | Oct 20, 2020 | This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template w... |
| CVE-2020-7748 | HIGH | 8.1 | 1.7% | Oct 20, 2020 | This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used a... |
| CVE-2020-7747 | MEDIUM | 6.3 | 0.9% | Oct 20, 2020 | This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a s... |
| CVE-2020-5640 | CRITICAL | 9.8 | 2.4% | Oct 20, 2020 | Local file inclusion vulnerability in OneThird CMS v1.96c and earlier allows a remote unauthenticated attacker to execut... |
| CVE-2020-15261 | MEDIUM | 6.7 | 11.1% | Oct 19, 2020 | On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally auth... |
| CVE-2020-15256 | CRITICAL | 9.8 | 1.5% | Oct 19, 2020 | A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerab... |
| CVE-2020-6085 | HIGH | 7.5 | 3.5% | Oct 19, 2020 | An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Br... |
| CVE-2020-6084 | HIGH | 7.5 | 3.5% | Oct 19, 2020 | An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Br... |
| CVE-2020-15263 | MEDIUM | 6.1 | 0.7% | Oct 19, 2020 | In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not e... |
| CVE-2020-15245 | MEDIUM | 4.3 | 0.6% | Oct 19, 2020 | In Sylius before versions 1.6.9, 1.7.9 and 1.8.3, the user may register in a shop by email mail@example.com, verify it, ... |
| CVE-2020-13937 | MEDIUM | 5.3 | 78.8% | Oct 19, 2020 | Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.... |
| CVE-2020-10746 | MEDIUM | 6.1 | 0.2% | Oct 19, 2020 | A flaw was found in Infinispan (org.infinispan:infinispan-server-runtime) version 10, where it permits local access to c... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now