2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10708Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-6279Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-6275CRITICAL9.8SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Serv...
CVE-2020-6271HIGH8.2SAP Solution Manager (Problem Context Manager), version 7.2, does not perform the necessary authentication, allowing an ...
CVE-2020-6270MEDIUM6.5SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not per...
CVE-2020-6269MEDIUM6.5Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access ...
CVE-2020-6268HIGH8.1Statutory Reporting for Insurance Companies in SAP ERP (EA-FINSERV versions - 600, 603, 604, 605, 606, 616, 617, 618, 80...
CVE-2020-6266MEDIUM5.4SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due t...
CVE-2020-6264HIGH7.5SAP Commerce, versions - 6.7, 1808, 1811, 1905, may allow an attacker to access information under certain conditions whi...
CVE-2020-6263CRITICAL9.8Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10,...
CVE-2020-6260MEDIUM5.3SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed ...
CVE-2020-6246MEDIUM6.1SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, ...
CVE-2020-6239MEDIUM4.4Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permission...
CVE-2020-4436HIGH7.5Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attac...
CVE-2020-4435HIGH7.5Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which ...
CVE-2020-4434HIGH7.5Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentic...
CVE-2020-4433HIGH7.5Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. Thi...
CVE-2020-4432HIGH7.5Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an att...
CVE-2020-7280HIGH7.8Privilege Escalation vulnerability during daily DAT updates when using McAfee Virus Scan Enterprise (VSE) prior to 8.8 P...
CVE-2020-7279HIGH7.8DLL Search Order Hijacking Vulnerability in the installer component of McAfee Host Intrusion Prevention System (Host IPS...
CVE-2020-13996HIGH8.8The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.
CVE-2020-8337MEDIUM6.7An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app as...
CVE-2020-8336MEDIUM6.8Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmwar...
CVE-2020-8334MEDIUM6.8The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which...
CVE-2020-8331Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now