2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6302HIGH8.1SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is...
CVE-2020-6288MEDIUM5.3SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit docum...
CVE-2020-6283MEDIUM6.1SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the m...
CVE-2020-14342HIGH7It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to...
CVE-2020-7325HIGH7.8Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files wh...
CVE-2020-7324MEDIUM6.1Improper Access Control vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to bypass secur...
CVE-2020-7323MEDIUM6.9Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2...
CVE-2020-7322MEDIUM4.7Information Disclosure Vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update...
CVE-2020-7320HIGH7.3Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 ...
CVE-2020-7319HIGH8.8Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Updat...
CVE-2020-5627MEDIUM6.1Yodobashi App for Android versions 1.8.7 and earlier allows remote attackers to lead a user to access an arbitrary websi...
CVE-2020-3679MEDIUM5.5u'During execution after Address Space Layout Randomization is turned on for QTEE, part of code is still mapped at known...
CVE-2020-3674MEDIUM5.5Information can leak into userspace due to improper transfer of data from kernel to userspace in Snapdragon Auto, Snapdr...
CVE-2020-3656HIGH7.8Out of bound access can happen in MHI command process due to lack of check of command channel id value received from MHI...
CVE-2020-3634CRITICAL9.1u'Multiple Read overflows issue due to improper length check while decoding Generic NAS transport/EMM info' in Snapdrago...
CVE-2020-3617HIGH7.1u'Buffer over-read Issue in Q6 testbus framework due to diag packet length is not completely validated before accessing ...
CVE-2020-11135HIGH7.5u'Reachable assertion when wrong data size is returned by parser for ape clips' in Snapdragon Auto, Snapdragon Consumer ...
CVE-2020-11129HIGH7.8u'During the error occurrence in capture request, the buffer is freed and later accessed causing the camera APP to fail ...
CVE-2020-11124HIGH7.8u'Possible use-after-free while accessing diag client map table since list can be reallocated due to exceeding max clien...
CVE-2020-4698MEDIUM5.4IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored...
CVE-2020-4516MEDIUM5.4IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-...
CVE-2020-3702MEDIUM6.5u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi...
CVE-2020-3675CRITICAL9.8u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute' ...
CVE-2020-3669CRITICAL9.8u'Buffer Overflow issue in WLAN tcp ip verification due to usage of out of range pointer offset' in Snapdragon Auto, Sna...
CVE-2020-3668CRITICAL9.8u'Buffer overflow while parsing PMF enabled MCBC frames due to frame length being lesser than what is expected while par...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now