2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-17497HIGH8.1eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAP...
CVE-2020-17446CRITICAL9.8asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database c...
CVE-2020-12674HIGH7.5In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of ze...
CVE-2020-12673HIGH7.5In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-...
CVE-2020-12100HIGH7.5In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denia...
CVE-2020-13291HIGH8.1In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.
CVE-2020-13290HIGH7.2In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page
CVE-2020-13288MEDIUM4.8In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page
CVE-2020-6310MEDIUM4.3Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions ...
CVE-2020-6309HIGH7.5SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11),...
CVE-2020-6301HIGH8.1SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthor...
CVE-2020-6300MEDIUM4.8SAP Business Objects Business Intelligence Platform (Central Management Console), versions- 4.2, 4.3, allows an attacker...
CVE-2020-6299MEDIUM4.3SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to a...
CVE-2020-6298HIGH8.1SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected B...
CVE-2020-6297MEDIUM4.4Under certain conditions the upgrade of SAP Data Hub 2.7 to SAP Data Intelligence, version - 3.0, allows an attacker to ...
CVE-2020-6296HIGH8.8SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, al...
CVE-2020-6295HIGH7.8Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensit...
CVE-2020-6294CRITICAL9.1Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any ...
CVE-2020-6293MEDIUM6.5SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a ...
CVE-2020-6284CRITICAL9SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script conten...
CVE-2020-6273MEDIUM4.3SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization check...
CVE-2020-2237MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Flaky Test Handler Plugin 1.0.4 and earlier allows attacker...
CVE-2020-2236MEDIUM5.4Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cros...
CVE-2020-2235MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows ...
CVE-2020-2234MEDIUM6.5A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now