2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9408HIGH8.8The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO ...
CVE-2020-1981HIGH7.8A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local at...
CVE-2020-1980HIGH7.8A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted she...
CVE-2020-1979HIGH7.8A format string vulnerability in the PAN-OS log daemon (logd) on Panorama allows a network based attacker with knowledge...
CVE-2020-1733MEDIUM5A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a play...
CVE-2020-8540CRITICAL9.8An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows rem...
CVE-2020-10181CRITICAL9.8goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevate...
CVE-2020-5203CRITICAL9.8In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled...
CVE-2020-10376CRITICAL9.8Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an...
CVE-2020-6210MEDIUM6.1SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the att...
CVE-2020-6209HIGH7.5SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allo...
CVE-2020-6208HIGH8.2SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic...
CVE-2020-6207CRITICAL9.8SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an...
CVE-2020-6206MEDIUM4.3SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning ma...
CVE-2020-6205MEDIUM6.1SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31,...
CVE-2020-6204MEDIUM4.3The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605...
CVE-2020-6203CRITICAL9.1SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to...
CVE-2020-6202HIGH7.2SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does...
CVE-2020-6201MEDIUM6.1The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled...
CVE-2020-6200MEDIUM5.4The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template ...
CVE-2020-6199MEDIUM5.4The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and ...
CVE-2020-6198CRITICAL9.8SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This...
CVE-2020-6197LOW3.3SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Exp...
CVE-2020-6196HIGH7.5SAP BusinessObjects Mobile (MobileBIService), version 4.2, allows an attacker to generate multiple requests, using which...
CVE-2020-6178MEDIUM5.4SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser his...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now