2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15468CRITICAL9.8Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.
CVE-2020-4029MEDIUM4.3The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, fro...
CVE-2020-4027MEDIUM4.7Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration per...
CVE-2020-4025MEDIUM4.8The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian ...
CVE-2020-4024MEDIUM5.4The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and...
CVE-2020-4022MEDIUM6.1The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and...
CVE-2020-14169MEDIUM6.1The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbit...
CVE-2020-14168MEDIUM5.9The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2...
CVE-2020-14167HIGH7.5The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8...
CVE-2020-14166MEDIUM4.8The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remo...
CVE-2020-14165MEDIUM5.3The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attack...
CVE-2020-14164MEDIUM6.1The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitr...
CVE-2020-5973MEDIUM4.4NVIDIA Virtual GPU Manager and the guest drivers contain a vulnerability in vGPU plugin, in which there is the potential...
CVE-2020-5972HIGH7.1NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which local pointer variables are not initial...
CVE-2020-5971HIGH7.8NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software reads from a buffer by usi...
CVE-2020-5970HIGH7.1NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, wh...
CVE-2020-5969MEDIUM6.3NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it validates a shared resource before u...
CVE-2020-5968HIGH7.8NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software does not restrict or incor...
CVE-2020-14947HIGH8.8OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php bec...
CVE-2020-9414HIGH8.8The MFT admin service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center and TIBCO Managed Fi...
CVE-2020-9413CRITICAL9.6The MFT Browser file transfer client and MFT Browser admin client components of TIBCO Software Inc.'s TIBCO Managed File...
CVE-2020-7049HIGH7.3Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection.
CVE-2020-14474HIGH7.5The Cellebrite UFED physical device 5.0 through 7.5.0.845 relies on key material hardcoded within both the executable co...
CVE-2020-14059MEDIUM6.5An issue was discovered in Squid 5.x before 5.0.3. Due to an Incorrect Synchronization, a Denial of Service can occur wh...
CVE-2020-14058HIGH7.5An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now