2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-2305MEDIUM6.5Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks...
CVE-2020-2304MEDIUM6.5Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) atta...
CVE-2020-2303MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers t...
CVE-2020-2302MEDIUM4.3A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permis...
CVE-2020-1908MEDIUM4.6Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could hav...
CVE-2020-4785MEDIUM5.4IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hi...
CVE-2020-4649MEDIUM4.3IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by...
CVE-2020-6557MEDIUM6.5Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform d...
CVE-2020-15989MEDIUM5.5Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sens...
CVE-2020-15988MEDIUM6.3Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allowed a remote attacker...
CVE-2020-15986MEDIUM6.5Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap c...
CVE-2020-15985MEDIUM6.5Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to spoof security...
CVE-2020-15984MEDIUM6.5Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a remote attacker to sp...
CVE-2020-15982MEDIUM6.5Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potenti...
CVE-2020-15981MEDIUM6.5Out of bounds read in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensi...
CVE-2020-15977MEDIUM6.5Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obta...
CVE-2020-15973MEDIUM6.5Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a...
CVE-2020-7757MEDIUM6.5This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a ...
CVE-2020-26939MEDIUM5.3In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information abou...
CVE-2020-23989MEDIUM5.4NeDi 1.9C allows pwsec.php oid XSS.
CVE-2020-23868MEDIUM5.4NeDi 1.9C allows inc/rt-popup.php d XSS.
CVE-2020-8236MEDIUM6.8A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two ...
CVE-2020-6014MEDIUM6.5Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83...
CVE-2020-5657MEDIUM6.5Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function incl...
CVE-2020-28044MEDIUM6.8An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in manage...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now