2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9408 | HIGH | 8.8 | 1.3% | Mar 11, 2020 | The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO ... |
| CVE-2020-1981 | HIGH | 7.8 | 0.4% | Mar 11, 2020 | A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local at... |
| CVE-2020-1980 | HIGH | 7.8 | 0.6% | Mar 11, 2020 | A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted she... |
| CVE-2020-1979 | HIGH | 7.8 | 1.0% | Mar 11, 2020 | A format string vulnerability in the PAN-OS log daemon (logd) on Panorama allows a network based attacker with knowledge... |
| CVE-2020-1733 | MEDIUM | 5 | 0.4% | Mar 11, 2020 | A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a play... |
| CVE-2020-8540 | CRITICAL | 9.8 | 12.5% | Mar 11, 2020 | An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows rem... |
| CVE-2020-10181 | CRITICAL | 9.8 | 14.2% | Mar 11, 2020 | goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevate... |
| CVE-2020-5203 | CRITICAL | 9.8 | 2.1% | Mar 11, 2020 | In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled... |
| CVE-2020-10376 | CRITICAL | 9.8 | 1.1% | Mar 11, 2020 | Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an... |
| CVE-2020-6210 | MEDIUM | 6.1 | 0.7% | Mar 10, 2020 | SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the att... |
| CVE-2020-6209 | HIGH | 7.5 | 0.8% | Mar 10, 2020 | SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allo... |
| CVE-2020-6208 | HIGH | 8.2 | 1.1% | Mar 10, 2020 | SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic... |
| CVE-2020-6207 | CRITICAL | 9.8 | 98.4% | Mar 10, 2020 | SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an... |
| CVE-2020-6206 | MEDIUM | 4.3 | 0.4% | Mar 10, 2020 | SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning ma... |
| CVE-2020-6205 | MEDIUM | 6.1 | 0.7% | Mar 10, 2020 | SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31,... |
| CVE-2020-6204 | MEDIUM | 4.3 | 0.6% | Mar 10, 2020 | The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605... |
| CVE-2020-6203 | CRITICAL | 9.1 | 1.9% | Mar 10, 2020 | SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to... |
| CVE-2020-6202 | HIGH | 7.2 | 1.1% | Mar 10, 2020 | SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does... |
| CVE-2020-6201 | MEDIUM | 6.1 | 0.8% | Mar 10, 2020 | The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled... |
| CVE-2020-6200 | MEDIUM | 5.4 | 0.5% | Mar 10, 2020 | The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template ... |
| CVE-2020-6199 | MEDIUM | 5.4 | 0.3% | Mar 10, 2020 | The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and ... |
| CVE-2020-6198 | CRITICAL | 9.8 | 1.4% | Mar 10, 2020 | SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This... |
| CVE-2020-6197 | LOW | 3.3 | 0.6% | Mar 10, 2020 | SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Exp... |
| CVE-2020-6196 | HIGH | 7.5 | 1.4% | Mar 10, 2020 | SAP BusinessObjects Mobile (MobileBIService), version 4.2, allows an attacker to generate multiple requests, using which... |
| CVE-2020-6178 | MEDIUM | 5.4 | 0.7% | Mar 10, 2020 | SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser his... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now