2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-14348MEDIUM4.3It was found in AMQ Online before 1.5.2 that injecting an invalid field to a user's AddressSpace configuration of the us...
CVE-2020-13928MEDIUM6.1Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitize...
CVE-2020-10748MEDIUM6.1A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circ...
CVE-2020-10715MEDIUM4.3A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft ...
CVE-2020-3990MEDIUM6.5VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an information disclosure vulnerabil...
CVE-2020-3988MEDIUM6.1VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability ...
CVE-2020-3987MEDIUM6.1VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability ...
CVE-2020-3986MEDIUM6.1VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability ...
CVE-2020-3980MEDIUM6.7VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configuring the system wide ...
CVE-2020-7529MEDIUM5.5A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAP...
CVE-2020-4708MEDIUM5.3IBM Security Trusteer Pinpoint Detect 11.6.5 could disclose some information due to using a wildcard in the Access-Contr...
CVE-2020-24890MEDIUM5.5libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in...
CVE-2020-1710MEDIUM5.3The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a ...
CVE-2020-2278MEDIUM6.5Jenkins Storable Configs Plugin 1.0 and earlier does not restrict the user-specified file name, allowing attackers with ...
CVE-2020-2277MEDIUM6.5Jenkins Storable Configs Plugin 1.0 and earlier allows users with Job/Read permission to read arbitrary files on the Jen...
CVE-2020-2275MEDIUM6.5Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins co...
CVE-2020-2274MEDIUM5.5Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the...
CVE-2020-2273MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers to conne...
CVE-2020-2272MEDIUM4.3A missing permission check in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers with Overall/Read permission to...
CVE-2020-2271MEDIUM5.4Jenkins Locked Files Report Plugin 1.6 and earlier does not escape locked files' names in tooltips, resulting in a store...
CVE-2020-2270MEDIUM5.4Jenkins ClearCase Release Plugin 0.3 and earlier does not escape the composite baseline in badge tooltip, resulting in a...
CVE-2020-2269MEDIUM5.4Jenkins chosen-views-tabbar Plugin 1.2 and earlier does not escape view names in the dropdown to select views, resulting...
CVE-2020-2267MEDIUM4.3A missing permission check in Jenkins MongoDB Plugin 1.3 and earlier allows attackers with Overall/Read permission to ga...
CVE-2020-2266MEDIUM5.4Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting i...
CVE-2020-2265MEDIUM5.4Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, re...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now