2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12699MEDIUM6.1The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.
CVE-2020-12698MEDIUM4.3The direct_mail extension through 5.2.3 for TYPO3 has Broken Access Control for newsletter subscriber tables.
CVE-2020-12697MEDIUM5.3The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log entries.
CVE-2020-10654CRITICAL9.8Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be...
CVE-2020-3341HIGH7.5A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could all...
CVE-2020-3327HIGH7.5A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an un...
CVE-2020-11932LOW2.3It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one wa...
CVE-2020-1718HIGH8.8A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gai...
CVE-2020-11058LOW2.2In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later...
CVE-2020-11057HIGH8.8In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute py...
CVE-2020-12772HIGH8.8An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can inclu...
CVE-2020-11062MEDIUM5.4In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type...
CVE-2020-11060HIGH8.8In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this v...
CVE-2020-12826MEDIUM5.3A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in ...
CVE-2020-6262HIGH8.8Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_...
CVE-2020-6259MEDIUM6.5Under certain conditions SAP Adaptive Server Enterprise, versions 15.7, 16.0, allows an attacker to access information w...
CVE-2020-6258MEDIUM6.5SAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowin...
CVE-2020-6257MEDIUM5.4SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) 4.2 does not sufficiently encode user-control...
CVE-2020-6256MEDIUM4.3SAP Master Data Governance, versions - 748, 749, 750, 751, 752, 800, 801, 802, 803, 804, allows users to display change ...
CVE-2020-6254MEDIUM6.1SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors,...
CVE-2020-6253HIGH7.2Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated us...
CVE-2020-6252HIGH8Under certain conditions SAP Adaptive Server Enterprise (Cockpit), version 16.0, allows an attacker with access to local...
CVE-2020-6251MEDIUM6.5Under certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, version 4.2, allows an ...
CVE-2020-6250MEDIUM6.8SAP Adaptive Server Enterprise, version 16.0, allows an authenticated attacker to exploit certain misconfigured endpoint...
CVE-2020-6249HIGH8.8The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now