2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6213 | MEDIUM | 6.1 | 0.8% | Apr 24, 2020 | SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750,... |
| CVE-2020-6212 | MEDIUM | 5.4 | 0.7% | Apr 24, 2020 | Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (version... |
| CVE-2020-12070 | HIGH | 7.5 | 2.0% | Apr 24, 2020 | The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulner... |
| CVE-2020-12245 | MEDIUM | 6.1 | 1.9% | Apr 24, 2020 | Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip. |
| CVE-2020-11004 | HIGH | 7.5 | 1.5% | Apr 24, 2020 | SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL quer... |
| CVE-2020-11013 | MEDIUM | 5 | 1.3% | Apr 24, 2020 | Their is an information disclosure vulnerability in Helm from version 3.1.0 and before version 3.2.0. `lookup` is a Helm... |
| CVE-2020-7134 | MEDIUM | 6.5 | 0.9% | Apr 24, 2020 | A remote access to sensitive data vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2... |
| CVE-2020-7133 | CRITICAL | 9.8 | 1.7% | Apr 24, 2020 | A unauthorized remote access vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2. |
| CVE-2020-1741 | MEDIUM | 5.9 | 0.9% | Apr 24, 2020 | A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified... |
| CVE-2020-7131 | CRITICAL | 9 | 1.1% | Apr 24, 2020 | This document describes a security vulnerability in Blade Maintenance Entity, Integrated Maintenance Entity and Maintena... |
| CVE-2020-6828 | HIGH | 7.5 | 1.5% | Apr 24, 2020 | A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentia... |
| CVE-2020-6827 | MEDIUM | 4.7 | 0.7% | Apr 24, 2020 | When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could... |
| CVE-2020-6826 | CRITICAL | 9.8 | 1.2% | Apr 24, 2020 | Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some ... |
| CVE-2020-6825 | CRITICAL | 9.8 | 1.9% | Apr 24, 2020 | Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox... |
| CVE-2020-6824 | LOW | 2.8 | 0.3% | Apr 24, 2020 | Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing ... |
| CVE-2020-6823 | CRITICAL | 9.8 | 1.6% | Apr 24, 2020 | A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, a... |
| CVE-2020-6822 | HIGH | 8.8 | 1.3% | Apr 24, 2020 | On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecod... |
| CVE-2020-6821 | HIGH | 7.5 | 1.5% | Apr 24, 2020 | When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method,... |
| CVE-2020-6820 | HIGH | 8.1 | 6.3% | Apr 24, 2020 | Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of t... |
| CVE-2020-6819 | HIGH | 8.1 | 3.0% | Apr 24, 2020 | Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aw... |
| CVE-2020-4267 | MEDIUM | 6.5 | 1.3% | Apr 24, 2020 | IBM MQ and MQ Appliance 8.0, 9.1 LTS, and 9.1 CD could allow an authenticated user cause a denial of service due to a me... |
| CVE-2020-5870 | HIGH | 8.1 | 0.5% | Apr 24, 2020 | In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for conne... |
| CVE-2020-5869 | CRITICAL | 9.1 | 0.5% | Apr 24, 2020 | In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to re... |
| CVE-2020-5868 | CRITICAL | 9.8 | 2.2% | Apr 24, 2020 | In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell c... |
| CVE-2020-12137 | MEDIUM | 6.1 | 2.3% | Apr 24, 2020 | GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior ma... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now