2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12062 | HIGH | 7.5 | 2.3% | Jun 1, 2020 | The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, whi... |
| CVE-2020-9071 | MEDIUM | 6.5 | 0.6% | Jun 1, 2020 | There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of t... |
| CVE-2020-7660 | HIGH | 8.1 | 3.0% | Jun 1, 2020 | serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" ... |
| CVE-2020-8967 | CRITICAL | 9.8 | 1.0% | Jun 1, 2020 | There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php file... |
| CVE-2020-12867 | MEDIUM | 5.5 | 0.5% | Jun 1, 2020 | A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to... |
| CVE-2020-7659 | HIGH | 7.5 | 1.3% | Jun 1, 2020 | reel through 0.6.1 allows Request Smuggling attacks due to incorrect Content-Length and Transfer encoding header parsing... |
| CVE-2020-6868 | MEDIUM | 6.5 | 0.6% | Jun 1, 2020 | There is an input validation vulnerability in a PON terminal product of ZTE, which supports the creation of WAN connecti... |
| CVE-2020-4023 | MEDIUM | 5.4 | 0.8% | Jun 1, 2020 | The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject ar... |
| CVE-2020-4021 | MEDIUM | 5.4 | 1.0% | Jun 1, 2020 | Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote a... |
| CVE-2020-4020 | HIGH | 7.2 | 1.7% | Jun 1, 2020 | The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who cont... |
| CVE-2020-4019 | HIGH | 7.8 | 0.4% | Jun 1, 2020 | The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the ap... |
| CVE-2020-4018 | HIGH | 8.8 | 0.6% | Jun 1, 2020 | The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup... |
| CVE-2020-4017 | MEDIUM | 5.3 | 1.2% | Jun 1, 2020 | The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible bef... |
| CVE-2020-4016 | MEDIUM | 5.3 | 1.2% | Jun 1, 2020 | The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before ve... |
| CVE-2020-4015 | MEDIUM | 4.3 | 1.0% | Jun 1, 2020 | The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers... |
| CVE-2020-4014 | MEDIUM | 4.3 | 0.8% | Jun 1, 2020 | The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to r... |
| CVE-2020-4013 | MEDIUM | 5.4 | 0.6% | Jun 1, 2020 | The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary H... |
| CVE-2020-8482 | MEDIUM | 5.5 | 0.3% | May 29, 2020 | Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauth... |
| CVE-2020-7654 | HIGH | 7.5 | 1.1% | May 29, 2020 | All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level ... |
| CVE-2020-7650 | MEDIUM | 6.5 | 1.1% | May 29, 2020 | All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows ar... |
| CVE-2020-7648 | MEDIUM | 6.5 | 1.1% | May 29, 2020 | All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for user... |
| CVE-2020-6937 | HIGH | 7.5 | 1.2% | May 29, 2020 | A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allo... |
| CVE-2020-11844 | CRITICAL | 9.8 | 2.0% | May 29, 2020 | Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybri... |
| CVE-2020-7653 | MEDIUM | 6.5 | 1.1% | May 29, 2020 | All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for user... |
| CVE-2020-7652 | MEDIUM | 6.5 | 1.7% | May 29, 2020 | All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for user... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now