2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6213MEDIUM6.1SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750,...
CVE-2020-6212MEDIUM5.4Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (version...
CVE-2020-12070HIGH7.5The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulner...
CVE-2020-12245MEDIUM6.1Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
CVE-2020-11004HIGH7.5SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL quer...
CVE-2020-11013MEDIUM5Their is an information disclosure vulnerability in Helm from version 3.1.0 and before version 3.2.0. `lookup` is a Helm...
CVE-2020-7134MEDIUM6.5A remote access to sensitive data vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2...
CVE-2020-7133CRITICAL9.8A unauthorized remote access vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2.
CVE-2020-1741MEDIUM5.9A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified...
CVE-2020-7131CRITICAL9This document describes a security vulnerability in Blade Maintenance Entity, Integrated Maintenance Entity and Maintena...
CVE-2020-6828HIGH7.5A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentia...
CVE-2020-6827MEDIUM4.7When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could...
CVE-2020-6826CRITICAL9.8Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some ...
CVE-2020-6825CRITICAL9.8Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox...
CVE-2020-6824LOW2.8Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing ...
CVE-2020-6823CRITICAL9.8A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, a...
CVE-2020-6822HIGH8.8On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecod...
CVE-2020-6821HIGH7.5When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method,...
CVE-2020-6820HIGH8.1Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of t...
CVE-2020-6819HIGH8.1Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aw...
CVE-2020-4267MEDIUM6.5IBM MQ and MQ Appliance 8.0, 9.1 LTS, and 9.1 CD could allow an authenticated user cause a denial of service due to a me...
CVE-2020-5870HIGH8.1In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for conne...
CVE-2020-5869CRITICAL9.1In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to re...
CVE-2020-5868CRITICAL9.8In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell c...
CVE-2020-12137MEDIUM6.1GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior ma...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now