2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12062HIGH7.5The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, whi...
CVE-2020-9071MEDIUM6.5There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of t...
CVE-2020-7660HIGH8.1serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" ...
CVE-2020-8967CRITICAL9.8There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php file...
CVE-2020-12867MEDIUM5.5A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to...
CVE-2020-7659HIGH7.5reel through 0.6.1 allows Request Smuggling attacks due to incorrect Content-Length and Transfer encoding header parsing...
CVE-2020-6868MEDIUM6.5There is an input validation vulnerability in a PON terminal product of ZTE, which supports the creation of WAN connecti...
CVE-2020-4023MEDIUM5.4The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject ar...
CVE-2020-4021MEDIUM5.4Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote a...
CVE-2020-4020HIGH7.2The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who cont...
CVE-2020-4019HIGH7.8The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the ap...
CVE-2020-4018HIGH8.8The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup...
CVE-2020-4017MEDIUM5.3The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible bef...
CVE-2020-4016MEDIUM5.3The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before ve...
CVE-2020-4015MEDIUM4.3The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers...
CVE-2020-4014MEDIUM4.3The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to r...
CVE-2020-4013MEDIUM5.4The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary H...
CVE-2020-8482MEDIUM5.5Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauth...
CVE-2020-7654HIGH7.5All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level ...
CVE-2020-7650MEDIUM6.5All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows ar...
CVE-2020-7648MEDIUM6.5All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for user...
CVE-2020-6937HIGH7.5A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allo...
CVE-2020-11844CRITICAL9.8Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybri...
CVE-2020-7653MEDIUM6.5All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for user...
CVE-2020-7652MEDIUM6.5All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for user...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now