2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6276MEDIUM6.1SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlle...
CVE-2020-6267MEDIUM5.4Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cooki...
CVE-2020-4513MEDIUM6.1IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...
CVE-2020-4512HIGH7.2IBM QRadar SIEM 7.3 and 7.4 could allow a remote privileged user to execute commands.
CVE-2020-4511MEDIUM6.5IBM QRadar SIEM 7.3 and 7.4 could allow an authenticated user to cause a denial of service of the qflow process by sendi...
CVE-2020-4510MEDIUM5.5IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r...
CVE-2020-4364MEDIUM5.4IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...
CVE-2020-15711HIGH8.8In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.
CVE-2020-13926CRITICAL9.8Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is f...
CVE-2020-13925CRITICAL9.8Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then exe...
CVE-2020-12025LOW3.3Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XX...
CVE-2020-11952MEDIUM6.2An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. Attackers...
CVE-2020-11951CRITICAL9.8An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is ...
CVE-2020-14300HIGH8.8The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-...
CVE-2020-15050HIGH7.5An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary fi...
CVE-2020-14298HIGH8.8The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrec...
CVE-2020-10989MEDIUM6.1An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to ex...
CVE-2020-10988CRITICAL9.8A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated...
CVE-2020-10987CRITICAL9.8The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary s...
CVE-2020-10986MEDIUM6.5A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to r...
CVE-2020-5766HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin f...
CVE-2020-11749CRITICAL9Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator ...
CVE-2020-15689HIGH7.5Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header th...
CVE-2020-14174MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project vi...
CVE-2020-15105MEDIUM5.4Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encod...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now