2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-14240MEDIUM6.1HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site ...
CVE-2020-14222MEDIUM6.1HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to ref...
CVE-2020-26506MEDIUM4.3An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0 allows users with lower priv...
CVE-2020-28047MEDIUM5.4AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration...
CVE-2020-15951MEDIUM6.1Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject ar...
CVE-2020-7762MEDIUM6.5This affects the package jsreport-chrome-pdf before 1.10.0.
CVE-2020-7761MEDIUM5.3This affects the package @absolunet/kafe before 3.2.10. It allows cause a denial of service when validating crafted inva...
CVE-2020-27691MEDIUM6.1The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Sett...
CVE-2020-27690MEDIUM5.5The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains a buffer overflow within its web mana...
CVE-2020-28049MEDIUM6.3An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time perio...
CVE-2020-22273MEDIUM6.5Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (suc...
CVE-2020-2319MEDIUM6.5Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file o...
CVE-2020-2318MEDIUM6.5Jenkins Mail Commander Plugin for Jenkins-ci Plugin 1.0.0 and earlier stores passwords unencrypted in job config.xml fil...
CVE-2020-2317MEDIUM5.4Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cros...
CVE-2020-2316MEDIUM5.4Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting ...
CVE-2020-2315MEDIUM6.5Jenkins Visualworks Store Plugin 1.1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE...
CVE-2020-2314MEDIUM5.5Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkin...
CVE-2020-2313MEDIUM4.3A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permissi...
CVE-2020-2312MEDIUM6.5Jenkins SQLPlus Script Runner Plugin 2.0.12 and earlier does not mask a password provided as command line argument in bu...
CVE-2020-2311MEDIUM4.3A missing permission check in Jenkins AWS Global Configuration Plugin 1.5 and earlier allows attackers with Overall/Read...
CVE-2020-2310MEDIUM4.3Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enum...
CVE-2020-2309MEDIUM4.3A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Re...
CVE-2020-2308MEDIUM4.3A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission...
CVE-2020-2307MEDIUM4.3Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller ...
CVE-2020-2306MEDIUM4.3A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now