2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14055 | MEDIUM | 6.1 | 0.7% | Jul 1, 2020 | Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insuff... |
| CVE-2020-2500 | MEDIUM | 6.5 | 0.7% | Jul 1, 2020 | This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers... |
| CVE-2020-5908 | MEDIUM | 5.5 | 0.3% | Jul 1, 2020 | In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in ... |
| CVE-2020-5905 | MEDIUM | 4.3 | 0.7% | Jul 1, 2020 | In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize ... |
| CVE-2020-5903 | MEDIUM | 6.1 | 2.2% | Jul 1, 2020 | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vuln... |
| CVE-2020-4414 | MEDIUM | 4.4 | 0.3% | Jul 1, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local at... |
| CVE-2020-4387 | MEDIUM | 4.7 | 0.2% | Jul 1, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us... |
| CVE-2020-4386 | MEDIUM | 4.7 | 0.2% | Jul 1, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us... |
| CVE-2020-4376 | MEDIUM | 6.5 | 1.1% | Jul 1, 2020 | IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow an attacker to cause a denial of service ca... |
| CVE-2020-4355 | MEDIUM | 5.3 | 2.2% | Jul 1, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a den... |
| CVE-2020-6261 | MEDIUM | 5.3 | 0.8% | Jul 1, 2020 | SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, ... |
| CVE-2020-15470 | MEDIUM | 5.5 | 0.7% | Jul 1, 2020 | ffjpeg through 2020-02-24 has a heap-based buffer overflow in jfif_decode in jfif.c. |
| CVE-2020-4029 | MEDIUM | 4.3 | 1.4% | Jul 1, 2020 | The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, fro... |
| CVE-2020-4027 | MEDIUM | 4.7 | 1.5% | Jul 1, 2020 | Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration per... |
| CVE-2020-4025 | MEDIUM | 4.8 | 0.9% | Jul 1, 2020 | The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian ... |
| CVE-2020-4024 | MEDIUM | 5.4 | 0.9% | Jul 1, 2020 | The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and... |
| CVE-2020-4022 | MEDIUM | 6.1 | 1.1% | Jul 1, 2020 | The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and... |
| CVE-2020-14169 | MEDIUM | 6.1 | 0.8% | Jul 1, 2020 | The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbit... |
| CVE-2020-14168 | MEDIUM | 5.9 | 1.7% | Jul 1, 2020 | The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2... |
| CVE-2020-14166 | MEDIUM | 4.8 | 1.9% | Jul 1, 2020 | The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remo... |
| CVE-2020-14165 | MEDIUM | 5.3 | 1.0% | Jul 1, 2020 | The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attack... |
| CVE-2020-14164 | MEDIUM | 6.1 | 0.7% | Jul 1, 2020 | The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitr... |
| CVE-2020-5973 | MEDIUM | 4.4 | 0.4% | Jun 30, 2020 | NVIDIA Virtual GPU Manager and the guest drivers contain a vulnerability in vGPU plugin, in which there is the potential... |
| CVE-2020-5969 | MEDIUM | 6.3 | 0.2% | Jun 30, 2020 | NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it validates a shared resource before u... |
| CVE-2020-14059 | MEDIUM | 6.5 | 4.4% | Jun 30, 2020 | An issue was discovered in Squid 5.x before 5.0.3. Due to an Incorrect Synchronization, a Denial of Service can occur wh... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now