2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2305 | MEDIUM | 6.5 | 1.4% | Nov 4, 2020 | Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks... |
| CVE-2020-2304 | MEDIUM | 6.5 | 1.5% | Nov 4, 2020 | Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) atta... |
| CVE-2020-2303 | MEDIUM | 4.3 | 0.7% | Nov 4, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers t... |
| CVE-2020-2302 | MEDIUM | 4.3 | 0.7% | Nov 4, 2020 | A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permis... |
| CVE-2020-1908 | MEDIUM | 4.6 | 0.3% | Nov 3, 2020 | Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could hav... |
| CVE-2020-4785 | MEDIUM | 5.4 | 0.7% | Nov 3, 2020 | IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hi... |
| CVE-2020-4649 | MEDIUM | 4.3 | 0.8% | Nov 3, 2020 | IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by... |
| CVE-2020-6557 | MEDIUM | 6.5 | 1.5% | Nov 3, 2020 | Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform d... |
| CVE-2020-15989 | MEDIUM | 5.5 | 1.1% | Nov 3, 2020 | Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sens... |
| CVE-2020-15988 | MEDIUM | 6.3 | 1.2% | Nov 3, 2020 | Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allowed a remote attacker... |
| CVE-2020-15986 | MEDIUM | 6.5 | 1.3% | Nov 3, 2020 | Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap c... |
| CVE-2020-15985 | MEDIUM | 6.5 | 1.6% | Nov 3, 2020 | Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to spoof security... |
| CVE-2020-15984 | MEDIUM | 6.5 | 1.3% | Nov 3, 2020 | Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a remote attacker to sp... |
| CVE-2020-15982 | MEDIUM | 6.5 | 1.4% | Nov 3, 2020 | Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potenti... |
| CVE-2020-15981 | MEDIUM | 6.5 | 1.4% | Nov 3, 2020 | Out of bounds read in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensi... |
| CVE-2020-15977 | MEDIUM | 6.5 | 1.5% | Nov 3, 2020 | Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obta... |
| CVE-2020-15973 | MEDIUM | 6.5 | 1.0% | Nov 3, 2020 | Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a... |
| CVE-2020-7757 | MEDIUM | 6.5 | 1.5% | Nov 2, 2020 | This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a ... |
| CVE-2020-26939 | MEDIUM | 5.3 | 0.9% | Nov 2, 2020 | In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information abou... |
| CVE-2020-23989 | MEDIUM | 5.4 | 0.5% | Nov 2, 2020 | NeDi 1.9C allows pwsec.php oid XSS. |
| CVE-2020-23868 | MEDIUM | 5.4 | 0.5% | Nov 2, 2020 | NeDi 1.9C allows inc/rt-popup.php d XSS. |
| CVE-2020-8236 | MEDIUM | 6.8 | 0.6% | Nov 2, 2020 | A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two ... |
| CVE-2020-6014 | MEDIUM | 6.5 | 0.4% | Nov 2, 2020 | Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83... |
| CVE-2020-5657 | MEDIUM | 6.5 | 1.1% | Nov 2, 2020 | Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function incl... |
| CVE-2020-28044 | MEDIUM | 6.8 | 0.3% | Nov 2, 2020 | An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in manage... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now