2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14348 | MEDIUM | 4.3 | 0.8% | Sep 16, 2020 | It was found in AMQ Online before 1.5.2 that injecting an invalid field to a user's AddressSpace configuration of the us... |
| CVE-2020-13928 | MEDIUM | 6.1 | 2.6% | Sep 16, 2020 | Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitize... |
| CVE-2020-10748 | MEDIUM | 6.1 | 0.9% | Sep 16, 2020 | A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circ... |
| CVE-2020-10715 | MEDIUM | 4.3 | 0.9% | Sep 16, 2020 | A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft ... |
| CVE-2020-3990 | MEDIUM | 6.5 | 0.3% | Sep 16, 2020 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an information disclosure vulnerabil... |
| CVE-2020-3988 | MEDIUM | 6.1 | 0.3% | Sep 16, 2020 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability ... |
| CVE-2020-3987 | MEDIUM | 6.1 | 0.3% | Sep 16, 2020 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability ... |
| CVE-2020-3986 | MEDIUM | 6.1 | 0.3% | Sep 16, 2020 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability ... |
| CVE-2020-3980 | MEDIUM | 6.7 | 0.3% | Sep 16, 2020 | VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configuring the system wide ... |
| CVE-2020-7529 | MEDIUM | 5.5 | 0.9% | Sep 16, 2020 | A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAP... |
| CVE-2020-4708 | MEDIUM | 5.3 | 1.0% | Sep 16, 2020 | IBM Security Trusteer Pinpoint Detect 11.6.5 could disclose some information due to using a wildcard in the Access-Contr... |
| CVE-2020-24890 | MEDIUM | 5.5 | 1.6% | Sep 16, 2020 | libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in... |
| CVE-2020-1710 | MEDIUM | 5.3 | 1.2% | Sep 16, 2020 | The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a ... |
| CVE-2020-2278 | MEDIUM | 6.5 | 1.4% | Sep 16, 2020 | Jenkins Storable Configs Plugin 1.0 and earlier does not restrict the user-specified file name, allowing attackers with ... |
| CVE-2020-2277 | MEDIUM | 6.5 | 1.7% | Sep 16, 2020 | Jenkins Storable Configs Plugin 1.0 and earlier allows users with Job/Read permission to read arbitrary files on the Jen... |
| CVE-2020-2275 | MEDIUM | 6.5 | 1.7% | Sep 16, 2020 | Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins co... |
| CVE-2020-2274 | MEDIUM | 5.5 | 0.3% | Sep 16, 2020 | Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the... |
| CVE-2020-2273 | MEDIUM | 4.3 | 0.7% | Sep 16, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers to conne... |
| CVE-2020-2272 | MEDIUM | 4.3 | 0.7% | Sep 16, 2020 | A missing permission check in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers with Overall/Read permission to... |
| CVE-2020-2271 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Locked Files Report Plugin 1.6 and earlier does not escape locked files' names in tooltips, resulting in a store... |
| CVE-2020-2270 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins ClearCase Release Plugin 0.3 and earlier does not escape the composite baseline in badge tooltip, resulting in a... |
| CVE-2020-2269 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins chosen-views-tabbar Plugin 1.2 and earlier does not escape view names in the dropdown to select views, resulting... |
| CVE-2020-2267 | MEDIUM | 4.3 | 0.7% | Sep 16, 2020 | A missing permission check in Jenkins MongoDB Plugin 1.3 and earlier allows attackers with Overall/Read permission to ga... |
| CVE-2020-2266 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting i... |
| CVE-2020-2265 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, re... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now