2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6302 | HIGH | 8.1 | 0.8% | Sep 9, 2020 | SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is... |
| CVE-2020-6288 | MEDIUM | 5.3 | 0.7% | Sep 9, 2020 | SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit docum... |
| CVE-2020-6283 | MEDIUM | 6.1 | 0.7% | Sep 9, 2020 | SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the m... |
| CVE-2020-14342 | HIGH | 7 | 0.7% | Sep 9, 2020 | It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to... |
| CVE-2020-7325 | HIGH | 7.8 | 0.3% | Sep 9, 2020 | Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files wh... |
| CVE-2020-7324 | MEDIUM | 6.1 | 0.3% | Sep 9, 2020 | Improper Access Control vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to bypass secur... |
| CVE-2020-7323 | MEDIUM | 6.9 | 0.3% | Sep 9, 2020 | Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2... |
| CVE-2020-7322 | MEDIUM | 4.7 | 0.2% | Sep 9, 2020 | Information Disclosure Vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update... |
| CVE-2020-7320 | HIGH | 7.3 | 0.3% | Sep 9, 2020 | Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 ... |
| CVE-2020-7319 | HIGH | 8.8 | 0.4% | Sep 9, 2020 | Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Updat... |
| CVE-2020-5627 | MEDIUM | 6.1 | 0.9% | Sep 9, 2020 | Yodobashi App for Android versions 1.8.7 and earlier allows remote attackers to lead a user to access an arbitrary websi... |
| CVE-2020-3679 | MEDIUM | 5.5 | 0.3% | Sep 9, 2020 | u'During execution after Address Space Layout Randomization is turned on for QTEE, part of code is still mapped at known... |
| CVE-2020-3674 | MEDIUM | 5.5 | 0.2% | Sep 9, 2020 | Information can leak into userspace due to improper transfer of data from kernel to userspace in Snapdragon Auto, Snapdr... |
| CVE-2020-3656 | HIGH | 7.8 | 0.2% | Sep 9, 2020 | Out of bound access can happen in MHI command process due to lack of check of command channel id value received from MHI... |
| CVE-2020-3634 | CRITICAL | 9.1 | 1.1% | Sep 9, 2020 | u'Multiple Read overflows issue due to improper length check while decoding Generic NAS transport/EMM info' in Snapdrago... |
| CVE-2020-3617 | HIGH | 7.1 | 0.2% | Sep 9, 2020 | u'Buffer over-read Issue in Q6 testbus framework due to diag packet length is not completely validated before accessing ... |
| CVE-2020-11135 | HIGH | 7.5 | 0.7% | Sep 9, 2020 | u'Reachable assertion when wrong data size is returned by parser for ape clips' in Snapdragon Auto, Snapdragon Consumer ... |
| CVE-2020-11129 | HIGH | 7.8 | 0.2% | Sep 9, 2020 | u'During the error occurrence in capture request, the buffer is freed and later accessed causing the camera APP to fail ... |
| CVE-2020-11124 | HIGH | 7.8 | 0.2% | Sep 9, 2020 | u'Possible use-after-free while accessing diag client map table since list can be reallocated due to exceeding max clien... |
| CVE-2020-4698 | MEDIUM | 5.4 | 0.6% | Sep 8, 2020 | IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored... |
| CVE-2020-4516 | MEDIUM | 5.4 | 0.8% | Sep 8, 2020 | IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-... |
| CVE-2020-3702 | MEDIUM | 6.5 | 0.3% | Sep 8, 2020 | u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi... |
| CVE-2020-3675 | CRITICAL | 9.8 | 1.1% | Sep 8, 2020 | u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute' ... |
| CVE-2020-3669 | CRITICAL | 9.8 | 1.1% | Sep 8, 2020 | u'Buffer Overflow issue in WLAN tcp ip verification due to usage of out of range pointer offset' in Snapdragon Auto, Sna... |
| CVE-2020-3668 | CRITICAL | 9.8 | 1.1% | Sep 8, 2020 | u'Buffer overflow while parsing PMF enabled MCBC frames due to frame length being lesser than what is expected while par... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now