2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-5968HIGH7.8NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software does not restrict or incor...
CVE-2020-14947HIGH8.8OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php bec...
CVE-2020-9414HIGH8.8The MFT admin service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center and TIBCO Managed Fi...
CVE-2020-7049HIGH7.3Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection.
CVE-2020-14474HIGH7.5The Cellebrite UFED physical device 5.0 through 7.5.0.845 relies on key material hardcoded within both the executable co...
CVE-2020-14058HIGH7.5An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid...
CVE-2020-15049HIGH8.8An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggli...
CVE-2020-14482HIGH7.8Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Opening a specially crafted project file may overflow...
CVE-2020-15087HIGH8.8In Presto before version 337, authenticated users can bypass authorization checks by directly accessing internal APIs. T...
CVE-2020-13095HIGH8.8Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the use...
CVE-2020-4044HIGH7.8The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious pa...
CVE-2020-9483HIGH7.5**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is ...
CVE-2020-14957HIGH7.8In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) ...
CVE-2020-14956HIGH7.8In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) ...
CVE-2020-7816HIGH7.8A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticate...
CVE-2020-15397HIGH7.8HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileg...
CVE-2020-15396HIGH7.8In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. B...
CVE-2020-5603HIGH7.5Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Conf...
CVE-2020-5602HIGH7.5Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configura...
CVE-2020-5601HIGH8.8Chrome Extension for e-Tax Reception System Ver1.0.0.0 allows remote attackers to execute an arbitrary command via unspe...
CVE-2020-5584HIGH7.5Cybozu Garoon 4.0.0 to 5.0.1 allow remote attackers to obtain unintended information via unspecified vectors.
CVE-2020-5580HIGH8.1Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to view and/or alter Sin...
CVE-2020-15395HIGH7.8In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multi...
CVE-2020-4067HIGH7.5In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There...
CVE-2020-14414HIGH8.8NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a POST reque...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now