2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14240 | MEDIUM | 6.1 | 0.7% | Nov 5, 2020 | HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site ... |
| CVE-2020-14222 | MEDIUM | 6.1 | 0.6% | Nov 5, 2020 | HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to ref... |
| CVE-2020-26506 | MEDIUM | 4.3 | 0.8% | Nov 5, 2020 | An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0 allows users with lower priv... |
| CVE-2020-28047 | MEDIUM | 5.4 | 0.8% | Nov 5, 2020 | AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration... |
| CVE-2020-15951 | MEDIUM | 6.1 | 1.0% | Nov 5, 2020 | Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject ar... |
| CVE-2020-7762 | MEDIUM | 6.5 | 1.6% | Nov 5, 2020 | This affects the package jsreport-chrome-pdf before 1.10.0. |
| CVE-2020-7761 | MEDIUM | 5.3 | 1.6% | Nov 5, 2020 | This affects the package @absolunet/kafe before 3.2.10. It allows cause a denial of service when validating crafted inva... |
| CVE-2020-27691 | MEDIUM | 6.1 | 0.7% | Nov 4, 2020 | The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Sett... |
| CVE-2020-27690 | MEDIUM | 5.5 | 0.4% | Nov 4, 2020 | The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains a buffer overflow within its web mana... |
| CVE-2020-28049 | MEDIUM | 6.3 | 0.4% | Nov 4, 2020 | An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time perio... |
| CVE-2020-22273 | MEDIUM | 6.5 | 0.4% | Nov 4, 2020 | Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (suc... |
| CVE-2020-2319 | MEDIUM | 6.5 | 1.0% | Nov 4, 2020 | Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file o... |
| CVE-2020-2318 | MEDIUM | 6.5 | 1.0% | Nov 4, 2020 | Jenkins Mail Commander Plugin for Jenkins-ci Plugin 1.0.0 and earlier stores passwords unencrypted in job config.xml fil... |
| CVE-2020-2317 | MEDIUM | 5.4 | 0.9% | Nov 4, 2020 | Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cros... |
| CVE-2020-2316 | MEDIUM | 5.4 | 0.7% | Nov 4, 2020 | Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting ... |
| CVE-2020-2315 | MEDIUM | 6.5 | 1.1% | Nov 4, 2020 | Jenkins Visualworks Store Plugin 1.1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE... |
| CVE-2020-2314 | MEDIUM | 5.5 | 0.3% | Nov 4, 2020 | Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkin... |
| CVE-2020-2313 | MEDIUM | 4.3 | 0.8% | Nov 4, 2020 | A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permissi... |
| CVE-2020-2312 | MEDIUM | 6.5 | 1.0% | Nov 4, 2020 | Jenkins SQLPlus Script Runner Plugin 2.0.12 and earlier does not mask a password provided as command line argument in bu... |
| CVE-2020-2311 | MEDIUM | 4.3 | 0.8% | Nov 4, 2020 | A missing permission check in Jenkins AWS Global Configuration Plugin 1.5 and earlier allows attackers with Overall/Read... |
| CVE-2020-2310 | MEDIUM | 4.3 | 0.8% | Nov 4, 2020 | Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enum... |
| CVE-2020-2309 | MEDIUM | 4.3 | 1.1% | Nov 4, 2020 | A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Re... |
| CVE-2020-2308 | MEDIUM | 4.3 | 1.1% | Nov 4, 2020 | A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission... |
| CVE-2020-2307 | MEDIUM | 4.3 | 1.2% | Nov 4, 2020 | Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller ... |
| CVE-2020-2306 | MEDIUM | 4.3 | 1.1% | Nov 4, 2020 | A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now