2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-2264MEDIUM5.4Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored c...
CVE-2020-2263MEDIUM5.4Jenkins Radiator View Plugin 1.29 and earlier does not escape the full name of the jobs in tooltips, resulting in a stor...
CVE-2020-2262MEDIUM5.4Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cr...
CVE-2020-2260MEDIUM4.3A missing permission check in Jenkins Perfecto Plugin 1.17 and earlier allows attackers with Overall/Read permission to ...
CVE-2020-2259MEDIUM5.4Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored c...
CVE-2020-2258MEDIUM4.3Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP en...
CVE-2020-2257MEDIUM5.4Jenkins Validating String Parameter Plugin 2.4 and earlier does not escape various user-controlled fields, resulting in ...
CVE-2020-2256MEDIUM5.4Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as par...
CVE-2020-2255MEDIUM4.3A missing permission check in Jenkins Blue Ocean Plugin 1.23.2 and earlier allows attackers with Overall/Read permission...
CVE-2020-2254MEDIUM6.5Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacke...
CVE-2020-2253MEDIUM4.8Jenkins Email Extension Plugin 2.75 and earlier does not perform hostname validation when connecting to the configured S...
CVE-2020-2252MEDIUM4.8Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP serve...
CVE-2020-14392MEDIUM5.5An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to...
CVE-2020-10781MEDIUM5.5A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the...
CVE-2020-7268MEDIUM4.3Path Traversal vulnerability in McAfee McAfee Email Gateway (MEG) prior to 7.6.406 allows remote attackers to traverse t...
CVE-2020-7297MEDIUM5.7Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user t...
CVE-2020-10768MEDIUM5.5A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect bra...
CVE-2020-7296MEDIUM5.7Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user t...
CVE-2020-7295MEDIUM4.6Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user t...
CVE-2020-7294MEDIUM4.6Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user t...
CVE-2020-10767MEDIUM5.5A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Predicti...
CVE-2020-10766MEDIUM5.5A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling all...
CVE-2020-14385MEDIUM5.5A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an...
CVE-2020-14314MEDIUM5.5A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way...
CVE-2020-14304MEDIUM4.4A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of th...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now