2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6276 | MEDIUM | 6.1 | 0.7% | Jul 14, 2020 | SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlle... |
| CVE-2020-6267 | MEDIUM | 5.4 | 0.8% | Jul 14, 2020 | Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cooki... |
| CVE-2020-4513 | MEDIUM | 6.1 | 0.7% | Jul 14, 2020 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2020-4512 | HIGH | 7.2 | 2.0% | Jul 14, 2020 | IBM QRadar SIEM 7.3 and 7.4 could allow a remote privileged user to execute commands. |
| CVE-2020-4511 | MEDIUM | 6.5 | 1.1% | Jul 14, 2020 | IBM QRadar SIEM 7.3 and 7.4 could allow an authenticated user to cause a denial of service of the qflow process by sendi... |
| CVE-2020-4510 | MEDIUM | 5.5 | 2.0% | Jul 14, 2020 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r... |
| CVE-2020-4364 | MEDIUM | 5.4 | 0.6% | Jul 14, 2020 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2020-15711 | HIGH | 8.8 | 0.5% | Jul 14, 2020 | In MISP before 2.4.129, setting a favourite homepage was not CSRF protected. |
| CVE-2020-13926 | CRITICAL | 9.8 | 1.9% | Jul 14, 2020 | Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is f... |
| CVE-2020-13925 | CRITICAL | 9.8 | 19.9% | Jul 14, 2020 | Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then exe... |
| CVE-2020-12025 | LOW | 3.3 | 1.5% | Jul 14, 2020 | Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XX... |
| CVE-2020-11952 | MEDIUM | 6.2 | 0.5% | Jul 14, 2020 | An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. Attackers... |
| CVE-2020-11951 | CRITICAL | 9.8 | 1.7% | Jul 14, 2020 | An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is ... |
| CVE-2020-14300 | HIGH | 8.8 | 0.4% | Jul 13, 2020 | The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-... |
| CVE-2020-15050 | HIGH | 7.5 | 50.7% | Jul 13, 2020 | An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary fi... |
| CVE-2020-14298 | HIGH | 8.8 | 0.3% | Jul 13, 2020 | The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrec... |
| CVE-2020-10989 | MEDIUM | 6.1 | 0.9% | Jul 13, 2020 | An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to ex... |
| CVE-2020-10988 | CRITICAL | 9.8 | 2.8% | Jul 13, 2020 | A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated... |
| CVE-2020-10987 | CRITICAL | 9.8 | 79.7% | Jul 13, 2020 | The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary s... |
| CVE-2020-10986 | MEDIUM | 6.5 | 0.6% | Jul 13, 2020 | A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to r... |
| CVE-2020-5766 | HIGH | 7.5 | 6.1% | Jul 13, 2020 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin f... |
| CVE-2020-11749 | CRITICAL | 9 | 16.2% | Jul 13, 2020 | Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator ... |
| CVE-2020-15689 | HIGH | 7.5 | 1.3% | Jul 13, 2020 | Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header th... |
| CVE-2020-14174 | MEDIUM | 4.3 | 1.2% | Jul 13, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project vi... |
| CVE-2020-15105 | MEDIUM | 5.4 | 0.6% | Jul 10, 2020 | Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encod... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now