2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5968 | HIGH | 7.8 | 0.4% | Jun 30, 2020 | NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software does not restrict or incor... |
| CVE-2020-14947 | HIGH | 8.8 | 19.5% | Jun 30, 2020 | OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php bec... |
| CVE-2020-9414 | HIGH | 8.8 | 1.7% | Jun 30, 2020 | The MFT admin service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center and TIBCO Managed Fi... |
| CVE-2020-7049 | HIGH | 7.3 | 0.9% | Jun 30, 2020 | Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection. |
| CVE-2020-14474 | HIGH | 7.5 | 2.5% | Jun 30, 2020 | The Cellebrite UFED physical device 5.0 through 7.5.0.845 relies on key material hardcoded within both the executable co... |
| CVE-2020-14058 | HIGH | 7.5 | 2.6% | Jun 30, 2020 | An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid... |
| CVE-2020-15049 | HIGH | 8.8 | 5.7% | Jun 30, 2020 | An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggli... |
| CVE-2020-14482 | HIGH | 7.8 | 2.6% | Jun 30, 2020 | Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Opening a specially crafted project file may overflow... |
| CVE-2020-15087 | HIGH | 8.8 | 1.1% | Jun 30, 2020 | In Presto before version 337, authenticated users can bypass authorization checks by directly accessing internal APIs. T... |
| CVE-2020-13095 | HIGH | 8.8 | 1.9% | Jun 30, 2020 | Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the use... |
| CVE-2020-4044 | HIGH | 7.8 | 2.4% | Jun 30, 2020 | The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious pa... |
| CVE-2020-9483 | HIGH | 7.5 | 34.6% | Jun 30, 2020 | **Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is ... |
| CVE-2020-14957 | HIGH | 7.8 | 0.4% | Jun 30, 2020 | In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) ... |
| CVE-2020-14956 | HIGH | 7.8 | 0.4% | Jun 30, 2020 | In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) ... |
| CVE-2020-7816 | HIGH | 7.8 | 1.4% | Jun 30, 2020 | A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticate... |
| CVE-2020-15397 | HIGH | 7.8 | 0.5% | Jun 30, 2020 | HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileg... |
| CVE-2020-15396 | HIGH | 7.8 | 0.4% | Jun 30, 2020 | In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. B... |
| CVE-2020-5603 | HIGH | 7.5 | 1.3% | Jun 30, 2020 | Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Conf... |
| CVE-2020-5602 | HIGH | 7.5 | 1.4% | Jun 30, 2020 | Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configura... |
| CVE-2020-5601 | HIGH | 8.8 | 1.6% | Jun 30, 2020 | Chrome Extension for e-Tax Reception System Ver1.0.0.0 allows remote attackers to execute an arbitrary command via unspe... |
| CVE-2020-5584 | HIGH | 7.5 | 1.3% | Jun 30, 2020 | Cybozu Garoon 4.0.0 to 5.0.1 allow remote attackers to obtain unintended information via unspecified vectors. |
| CVE-2020-5580 | HIGH | 8.1 | 1.1% | Jun 30, 2020 | Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to view and/or alter Sin... |
| CVE-2020-15395 | HIGH | 7.8 | 1.1% | Jun 30, 2020 | In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multi... |
| CVE-2020-4067 | HIGH | 7.5 | 1.8% | Jun 29, 2020 | In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There... |
| CVE-2020-14414 | HIGH | 8.8 | 3.7% | Jun 29, 2020 | NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a POST reque... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now