2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-17497 | HIGH | 8.1 | 0.7% | Aug 12, 2020 | eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAP... |
| CVE-2020-17446 | CRITICAL | 9.8 | 2.4% | Aug 12, 2020 | asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database c... |
| CVE-2020-12674 | HIGH | 7.5 | 6.2% | Aug 12, 2020 | In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of ze... |
| CVE-2020-12673 | HIGH | 7.5 | 6.2% | Aug 12, 2020 | In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-... |
| CVE-2020-12100 | HIGH | 7.5 | 5.2% | Aug 12, 2020 | In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denia... |
| CVE-2020-13291 | HIGH | 8.1 | 1.0% | Aug 12, 2020 | In GitLab before 13.2.3, project sharing could temporarily allow too permissive access. |
| CVE-2020-13290 | HIGH | 7.2 | 1.1% | Aug 12, 2020 | In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page |
| CVE-2020-13288 | MEDIUM | 4.8 | 4.0% | Aug 12, 2020 | In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page |
| CVE-2020-6310 | MEDIUM | 4.3 | 0.9% | Aug 12, 2020 | Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions ... |
| CVE-2020-6309 | HIGH | 7.5 | 1.8% | Aug 12, 2020 | SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11),... |
| CVE-2020-6301 | HIGH | 8.1 | 0.7% | Aug 12, 2020 | SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthor... |
| CVE-2020-6300 | MEDIUM | 4.8 | 0.5% | Aug 12, 2020 | SAP Business Objects Business Intelligence Platform (Central Management Console), versions- 4.2, 4.3, allows an attacker... |
| CVE-2020-6299 | MEDIUM | 4.3 | 0.9% | Aug 12, 2020 | SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to a... |
| CVE-2020-6298 | HIGH | 8.1 | 1.0% | Aug 12, 2020 | SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected B... |
| CVE-2020-6297 | MEDIUM | 4.4 | 0.3% | Aug 12, 2020 | Under certain conditions the upgrade of SAP Data Hub 2.7 to SAP Data Intelligence, version - 3.0, allows an attacker to ... |
| CVE-2020-6296 | HIGH | 8.8 | 1.3% | Aug 12, 2020 | SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, al... |
| CVE-2020-6295 | HIGH | 7.8 | 0.3% | Aug 12, 2020 | Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensit... |
| CVE-2020-6294 | CRITICAL | 9.1 | 1.5% | Aug 12, 2020 | Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any ... |
| CVE-2020-6293 | MEDIUM | 6.5 | 0.9% | Aug 12, 2020 | SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a ... |
| CVE-2020-6284 | CRITICAL | 9 | 1.8% | Aug 12, 2020 | SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script conten... |
| CVE-2020-6273 | MEDIUM | 4.3 | 0.6% | Aug 12, 2020 | SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization check... |
| CVE-2020-2237 | MEDIUM | 4.3 | 0.7% | Aug 12, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Flaky Test Handler Plugin 1.0.4 and earlier allows attacker... |
| CVE-2020-2236 | MEDIUM | 5.4 | 0.7% | Aug 12, 2020 | Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cros... |
| CVE-2020-2235 | MEDIUM | 6.5 | 0.9% | Aug 12, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows ... |
| CVE-2020-2234 | MEDIUM | 6.5 | 1.1% | Aug 12, 2020 | A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now