2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-2217MEDIUM6.1Jenkins Compatibility Action Storage Plugin 1.0 and earlier does not escape the content coming from the MongoDB in the t...
CVE-2020-2216MEDIUM4.3A missing permission check in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers with Overa...
CVE-2020-2215MEDIUM4.3A cross-site request forgery vulnerability in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows atta...
CVE-2020-2214MEDIUM5.4Jenkins ZAP Pipeline Plugin 1.9 and earlier programmatically disables Content-Security-Policy protection for user-genera...
CVE-2020-2213MEDIUM4.3Jenkins White Source Plugin 19.1.1 and earlier stores credentials unencrypted in its global configuration file and in jo...
CVE-2020-2212MEDIUM4.3Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on t...
CVE-2020-2210MEDIUM4.3Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier transmits configured passwords in plain text as part of its glob...
CVE-2020-2209MEDIUM4.3Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenki...
CVE-2020-2208MEDIUM4.3Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master wh...
CVE-2020-2207MEDIUM6.1Jenkins VncViewer Plugin 1.7 and earlier does not escape a parameter value in the checkVncServ form validation endpoint,...
CVE-2020-2206MEDIUM6.1Jenkins VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoi...
CVE-2020-2205MEDIUM4.8Jenkins VncRecorder Plugin 1.25 and earlier does not escape a tool path in the `checkVncServ` form validation endpoint, ...
CVE-2020-2204MEDIUM5.4A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read perm...
CVE-2020-2203MEDIUM4.3A cross-site request forgery vulnerability in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers to con...
CVE-2020-2202MEDIUM4.3A missing permission check in Jenkins Fortify on Demand Plugin 6.0.0 and earlier in form-related methods allowed users w...
CVE-2020-2201MEDIUM5.4Jenkins Sonargraph Integration Plugin 3.0.0 and earlier does not escape the file path for the Log file field form valida...
CVE-2020-9498MEDIUM6.7Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual chann...
CVE-2020-9497MEDIUM4.4Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If ...
CVE-2020-5909MEDIUM5.4In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface...
CVE-2020-3282MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communicati...
CVE-2020-3391MEDIUM6.5A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view...
CVE-2020-3340MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au...
CVE-2020-5238MEDIUM6.5The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs....
CVE-2020-15500MEDIUM6.1An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected u...
CVE-2020-14196MEDIUM5.3In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal we...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now