2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6375 | MEDIUM | 5.5 | 0.7% | Oct 15, 2020 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) ... |
| CVE-2020-6374 | HIGH | 7.8 | 1.2% | Oct 15, 2020 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received ... |
| CVE-2020-6373 | HIGH | 7.8 | 1.2% | Oct 15, 2020 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources... |
| CVE-2020-6372 | HIGH | 7.8 | 1.2% | Oct 15, 2020 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources... |
| CVE-2020-6371 | MEDIUM | 4.3 | 0.9% | Oct 15, 2020 | User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be expo... |
| CVE-2020-6368 | MEDIUM | 5.4 | 0.6% | Oct 15, 2020 | SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an att... |
| CVE-2020-6364 | CRITICAL | 10 | 6.4% | Oct 15, 2020 | SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an att... |
| CVE-2020-6363 | MEDIUM | 4.6 | 0.5% | Oct 15, 2020 | SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a us... |
| CVE-2020-6323 | MEDIUM | 6.1 | 0.6% | Oct 15, 2020 | SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-co... |
| CVE-2020-6319 | MEDIUM | 6.1 | 0.9% | Oct 15, 2020 | SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated... |
| CVE-2020-6272 | MEDIUM | 5.4 | 0.5% | Oct 15, 2020 | SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenti... |
| CVE-2020-8350 | HIGH | 8.8 | 0.6% | Oct 14, 2020 | An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 th... |
| CVE-2020-8349 | CRITICAL | 9.8 | 2.2% | Oct 14, 2020 | An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Op... |
| CVE-2020-8345 | HIGH | 7.8 | 0.4% | Oct 14, 2020 | A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feat... |
| CVE-2020-8338 | HIGH | 7.8 | 0.4% | Oct 14, 2020 | A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with ... |
| CVE-2020-8332 | MEDIUM | 6.4 | 0.2% | Oct 14, 2020 | A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo an... |
| CVE-2020-7383 | HIGH | 8.1 | 1.1% | Oct 14, 2020 | A SQL Injection issue in Rapid7 Nexpose version prior to 6.6.49 that may have allowed an authenticated user with a low p... |
| CVE-2020-7318 | MEDIUM | 4.3 | 1.0% | Oct 14, 2020 | Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10.9 Update 9 allows administrators t... |
| CVE-2020-7317 | MEDIUM | 4.3 | 0.3% | Oct 14, 2020 | Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows administrators t... |
| CVE-2020-3483 | MEDIUM | 6.3 | 0.1% | Oct 14, 2020 | Duo has identified and fixed an issue with the Duo Network Gateway (DNG) product in which some customer-provided SSL cer... |
| CVE-2020-3427 | HIGH | 7.8 | 0.3% | Oct 14, 2020 | The Windows Logon installer prior to 4.1.2 did not properly validate file installation paths. This allows an attacker wi... |
| CVE-2020-15253 | MEDIUM | 4.8 | 1.2% | Oct 14, 2020 | Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via the Create Shopping List module, that is rendered ... |
| CVE-2020-15229 | CRITICAL | 9.3 | 2.0% | Oct 14, 2020 | Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure ha... |
| CVE-2020-15224 | MEDIUM | 6.8 | 0.6% | Oct 14, 2020 | In Open Enclave before version 0.12.0, an information disclosure vulnerability exists when an enclave application using ... |
| CVE-2020-4395 | MEDIUM | 5.4 | 0.6% | Oct 14, 2020 | IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now