2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-17458MEDIUM5.4A post-authenticated stored XSS was found in MultiUx v.3.1.12.0 via the /multiux/SaveMailbox LastName field.
CVE-2020-25073MEDIUM5.3FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apa...
CVE-2020-8335MEDIUM6.8The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS ...
CVE-2020-6873MEDIUM5.3A ZTE product has a DoS vulnerability. Because the equipment couldn’t distinguish the attack packets and normal packets ...
CVE-2020-13946MEDIUM5.9In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local atta...
CVE-2020-23839MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpa...
CVE-2020-23835MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Mana...
CVE-2020-23831MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Stock Manag...
CVE-2020-23450MEDIUM5.4Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS...
CVE-2020-2251MEDIUM4.3Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain t...
CVE-2020-2250MEDIUM6.5Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml file...
CVE-2020-2248MEDIUM6.1Jenkins JSGames Plugin 0.2 and earlier evaluates part of a URL as code, resulting in a reflected cross-site scripting (X...
CVE-2020-2247MEDIUM6.5Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (...
CVE-2020-2246MEDIUM5.4Jenkins Valgrind Plugin 0.28 and earlier does not escape content in Valgrind XML reports, resulting in a stored cross-si...
CVE-2020-2244MEDIUM5.4Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, re...
CVE-2020-2243MEDIUM5.4Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips, resulting in a stored ...
CVE-2020-2242MEDIUM6.5A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenki...
CVE-2020-2239MEDIUM4.3Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration fi...
CVE-2020-2238MEDIUM5.4Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page...
CVE-2020-14514MEDIUM4.3All trailer Power Line Communications are affected. PLC bus traffic can be sniffed reliably via an active antenna up to ...
CVE-2020-15704MEDIUM5.5The modprobe child process in the ./debian/patches/load_ppp_generic_if_needed patch file incorrectly handled module load...
CVE-2020-25048MEDIUM4.6An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Q...
CVE-2020-25047MEDIUM5.5An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (released in China and India) software. The S ...
CVE-2020-25046MEDIUM5.5An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks addres...
CVE-2020-14364MEDIUM5An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue o...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now