2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-14055MEDIUM6.1Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insuff...
CVE-2020-2500MEDIUM6.5This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers...
CVE-2020-5908MEDIUM5.5In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in ...
CVE-2020-5905MEDIUM4.3In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize ...
CVE-2020-5903MEDIUM6.1In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vuln...
CVE-2020-4414MEDIUM4.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local at...
CVE-2020-4387MEDIUM4.7IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us...
CVE-2020-4386MEDIUM4.7IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us...
CVE-2020-4376MEDIUM6.5IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow an attacker to cause a denial of service ca...
CVE-2020-4355MEDIUM5.3IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a den...
CVE-2020-6261MEDIUM5.3SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, ...
CVE-2020-15470MEDIUM5.5ffjpeg through 2020-02-24 has a heap-based buffer overflow in jfif_decode in jfif.c.
CVE-2020-4029MEDIUM4.3The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, fro...
CVE-2020-4027MEDIUM4.7Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration per...
CVE-2020-4025MEDIUM4.8The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian ...
CVE-2020-4024MEDIUM5.4The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and...
CVE-2020-4022MEDIUM6.1The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and...
CVE-2020-14169MEDIUM6.1The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbit...
CVE-2020-14168MEDIUM5.9The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2...
CVE-2020-14166MEDIUM4.8The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remo...
CVE-2020-14165MEDIUM5.3The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attack...
CVE-2020-14164MEDIUM6.1The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitr...
CVE-2020-5973MEDIUM4.4NVIDIA Virtual GPU Manager and the guest drivers contain a vulnerability in vGPU plugin, in which there is the potential...
CVE-2020-5969MEDIUM6.3NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it validates a shared resource before u...
CVE-2020-14059MEDIUM6.5An issue was discovered in Squid 5.x before 5.0.3. Due to an Incorrect Synchronization, a Denial of Service can occur wh...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now