2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7209CRITICAL9.8LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
CVE-2020-7208MEDIUM6.1LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is resolved in release 6.0-2.
CVE-2020-6973MEDIUM6.2Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2. Multiple cr...
CVE-2020-5241MEDIUM5.4matestack-ui-core (RubyGem) before 0.7.4 is vulnerable to XSS/Script injection. This vulnerability is patched in version...
CVE-2020-6975MEDIUM4.9Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2. Successful ...
CVE-2020-1977HIGH8.8Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated att...
CVE-2020-1976MEDIUM5.5A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authentica...
CVE-2020-1975HIGH8.8Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authentica...
CVE-2020-8955CRITICAL9.8irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of se...
CVE-2020-5399HIGH7.4Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TL...
CVE-2020-8950HIGH7.8The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of p...
CVE-2020-6193MEDIUM6.1SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to...
CVE-2020-6192HIGH7.2SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root ...
CVE-2020-6191HIGH7.2SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with ro...
CVE-2020-6190MEDIUM5.8Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide ...
CVE-2020-6189MEDIUM5.3Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error mess...
CVE-2020-6188HIGH8.8VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700,...
CVE-2020-6187MEDIUM4.9SAP NetWeaver (Guided Procedures), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an ...
CVE-2020-6186HIGH7.5SAP Host Agent, version 7.21, allows an attacker to cause a slowdown in processing of username/password-based authentica...
CVE-2020-6185MEDIUM5.4Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS vers...
CVE-2020-6184MEDIUM6.1Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS ver...
CVE-2020-6183MEDIUM6.5SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sen...
CVE-2020-6181MEDIUM5.8Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP...
CVE-2020-6177MEDIUM4.3SAP Mobile Platform, version 3.0, does not sufficiently validate an XML document accepted from an untrusted source which...
CVE-2020-8949HIGH8.8Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572,...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now