2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2264 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored c... |
| CVE-2020-2263 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Radiator View Plugin 1.29 and earlier does not escape the full name of the jobs in tooltips, resulting in a stor... |
| CVE-2020-2262 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cr... |
| CVE-2020-2260 | MEDIUM | 4.3 | 0.7% | Sep 16, 2020 | A missing permission check in Jenkins Perfecto Plugin 1.17 and earlier allows attackers with Overall/Read permission to ... |
| CVE-2020-2259 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored c... |
| CVE-2020-2258 | MEDIUM | 4.3 | 0.7% | Sep 16, 2020 | Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP en... |
| CVE-2020-2257 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Validating String Parameter Plugin 2.4 and earlier does not escape various user-controlled fields, resulting in ... |
| CVE-2020-2256 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as par... |
| CVE-2020-2255 | MEDIUM | 4.3 | 0.8% | Sep 16, 2020 | A missing permission check in Jenkins Blue Ocean Plugin 1.23.2 and earlier allows attackers with Overall/Read permission... |
| CVE-2020-2254 | MEDIUM | 6.5 | 2.1% | Sep 16, 2020 | Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacke... |
| CVE-2020-2253 | MEDIUM | 4.8 | 0.7% | Sep 16, 2020 | Jenkins Email Extension Plugin 2.75 and earlier does not perform hostname validation when connecting to the configured S... |
| CVE-2020-2252 | MEDIUM | 4.8 | 1.0% | Sep 16, 2020 | Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP serve... |
| CVE-2020-14392 | MEDIUM | 5.5 | 0.6% | Sep 16, 2020 | An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to... |
| CVE-2020-10781 | MEDIUM | 5.5 | 0.3% | Sep 16, 2020 | A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the... |
| CVE-2020-7268 | MEDIUM | 4.3 | 1.0% | Sep 16, 2020 | Path Traversal vulnerability in McAfee McAfee Email Gateway (MEG) prior to 7.6.406 allows remote attackers to traverse t... |
| CVE-2020-7297 | MEDIUM | 5.7 | 0.4% | Sep 16, 2020 | Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user t... |
| CVE-2020-10768 | MEDIUM | 5.5 | 0.4% | Sep 16, 2020 | A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect bra... |
| CVE-2020-7296 | MEDIUM | 5.7 | 0.4% | Sep 15, 2020 | Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user t... |
| CVE-2020-7295 | MEDIUM | 4.6 | 0.5% | Sep 15, 2020 | Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user t... |
| CVE-2020-7294 | MEDIUM | 4.6 | 0.4% | Sep 15, 2020 | Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user t... |
| CVE-2020-10767 | MEDIUM | 5.5 | 0.4% | Sep 15, 2020 | A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Predicti... |
| CVE-2020-10766 | MEDIUM | 5.5 | 0.5% | Sep 15, 2020 | A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling all... |
| CVE-2020-14385 | MEDIUM | 5.5 | 0.4% | Sep 15, 2020 | A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an... |
| CVE-2020-14314 | MEDIUM | 5.5 | 0.4% | Sep 15, 2020 | A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way... |
| CVE-2020-14304 | MEDIUM | 4.4 | 0.4% | Sep 15, 2020 | A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of th... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now