2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6375MEDIUM5.5SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) ...
CVE-2020-6374HIGH7.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received ...
CVE-2020-6373HIGH7.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources...
CVE-2020-6372HIGH7.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources...
CVE-2020-6371MEDIUM4.3User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be expo...
CVE-2020-6368MEDIUM5.4SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an att...
CVE-2020-6364CRITICAL10SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an att...
CVE-2020-6363MEDIUM4.6SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a us...
CVE-2020-6323MEDIUM6.1SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-co...
CVE-2020-6319MEDIUM6.1SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated...
CVE-2020-6272MEDIUM5.4SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenti...
CVE-2020-8350HIGH8.8An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 th...
CVE-2020-8349CRITICAL9.8An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Op...
CVE-2020-8345HIGH7.8A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feat...
CVE-2020-8338HIGH7.8A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with ...
CVE-2020-8332MEDIUM6.4A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo an...
CVE-2020-7383HIGH8.1A SQL Injection issue in Rapid7 Nexpose version prior to 6.6.49 that may have allowed an authenticated user with a low p...
CVE-2020-7318MEDIUM4.3Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10.9 Update 9 allows administrators t...
CVE-2020-7317MEDIUM4.3Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows administrators t...
CVE-2020-3483MEDIUM6.3Duo has identified and fixed an issue with the Duo Network Gateway (DNG) product in which some customer-provided SSL cer...
CVE-2020-3427HIGH7.8The Windows Logon installer prior to 4.1.2 did not properly validate file installation paths. This allows an attacker wi...
CVE-2020-15253MEDIUM4.8Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via the Create Shopping List module, that is rendered ...
CVE-2020-15229CRITICAL9.3Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure ha...
CVE-2020-15224MEDIUM6.8In Open Enclave before version 0.12.0, an information disclosure vulnerability exists when an enclave application using ...
CVE-2020-4395MEDIUM5.4IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now