2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6248HIGH7.2SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an au...
CVE-2020-6247HIGH7.5SAP Business Objects Business Intelligence Platform, version 4.2, allows an unauthenticated attacker to prevent legitima...
CVE-2020-6245MEDIUM6.7SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to i...
CVE-2020-6244HIGH7.8SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious co...
CVE-2020-6243HIGH8.8Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not ...
CVE-2020-6242CRITICAL9.8SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an att...
CVE-2020-6241HIGH8.8SAP Adaptive Server Enterprise, version 16.0, allows an authenticated user to execute crafted database queries to elevat...
CVE-2020-6240HIGH7.5SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allo...
CVE-2020-1746MEDIUM5A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and...
CVE-2020-12825HIGH7.1libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption...
CVE-2020-12823CRITICAL9.8OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other im...
CVE-2020-5898MEDIUM5.5In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the use...
CVE-2020-5897HIGH8.8In versions 7.1.5-7.1.9, there is use-after-free memory vulnerability in the BIG-IP Edge Client Windows ActiveX componen...
CVE-2020-5896HIGH7.8On versions 7.1.5-7.1.9, the BIG-IP Edge Client's Windows Installer Service's temporary folder has weak file and folder ...
CVE-2020-5248MEDIUM5.3GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used o...
CVE-2020-1939CRITICAL9.8The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional co...
CVE-2020-9310Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-4346MEDIUM5.3IBM API Connect's V2018.4.1.0 through 2018.4.1.10 management server has an unsecured api which can be exploited by an un...
CVE-2020-4195MEDIUM5.4IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victi...
CVE-2020-1763HIGH7.5An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unau...
CVE-2020-10741Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-12826. Reason: This candidate is a duplicate of ...
CVE-2020-10706MEDIUM6.6A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at res...
CVE-2020-8159CRITICAL9.8There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a w...
CVE-2020-8156HIGH7A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
CVE-2020-8155MEDIUM5.4An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerab...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now