2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2217 | MEDIUM | 6.1 | 0.7% | Jul 2, 2020 | Jenkins Compatibility Action Storage Plugin 1.0 and earlier does not escape the content coming from the MongoDB in the t... |
| CVE-2020-2216 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | A missing permission check in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers with Overa... |
| CVE-2020-2215 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | A cross-site request forgery vulnerability in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows atta... |
| CVE-2020-2214 | MEDIUM | 5.4 | 0.7% | Jul 2, 2020 | Jenkins ZAP Pipeline Plugin 1.9 and earlier programmatically disables Content-Security-Policy protection for user-genera... |
| CVE-2020-2213 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | Jenkins White Source Plugin 19.1.1 and earlier stores credentials unencrypted in its global configuration file and in jo... |
| CVE-2020-2212 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on t... |
| CVE-2020-2210 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier transmits configured passwords in plain text as part of its glob... |
| CVE-2020-2209 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenki... |
| CVE-2020-2208 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master wh... |
| CVE-2020-2207 | MEDIUM | 6.1 | 0.9% | Jul 2, 2020 | Jenkins VncViewer Plugin 1.7 and earlier does not escape a parameter value in the checkVncServ form validation endpoint,... |
| CVE-2020-2206 | MEDIUM | 6.1 | 0.9% | Jul 2, 2020 | Jenkins VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoi... |
| CVE-2020-2205 | MEDIUM | 4.8 | 0.7% | Jul 2, 2020 | Jenkins VncRecorder Plugin 1.25 and earlier does not escape a tool path in the `checkVncServ` form validation endpoint, ... |
| CVE-2020-2204 | MEDIUM | 5.4 | 0.6% | Jul 2, 2020 | A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read perm... |
| CVE-2020-2203 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | A cross-site request forgery vulnerability in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers to con... |
| CVE-2020-2202 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | A missing permission check in Jenkins Fortify on Demand Plugin 6.0.0 and earlier in form-related methods allowed users w... |
| CVE-2020-2201 | MEDIUM | 5.4 | 0.7% | Jul 2, 2020 | Jenkins Sonargraph Integration Plugin 3.0.0 and earlier does not escape the file path for the Log file field form valida... |
| CVE-2020-9498 | MEDIUM | 6.7 | 0.7% | Jul 2, 2020 | Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual chann... |
| CVE-2020-9497 | MEDIUM | 4.4 | 0.8% | Jul 2, 2020 | Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If ... |
| CVE-2020-5909 | MEDIUM | 5.4 | 0.4% | Jul 2, 2020 | In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface... |
| CVE-2020-3282 | MEDIUM | 6.1 | 0.8% | Jul 2, 2020 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communicati... |
| CVE-2020-3391 | MEDIUM | 6.5 | 1.3% | Jul 2, 2020 | A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view... |
| CVE-2020-3340 | MEDIUM | 4.8 | 0.6% | Jul 2, 2020 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au... |
| CVE-2020-5238 | MEDIUM | 6.5 | 1.6% | Jul 1, 2020 | The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs.... |
| CVE-2020-15500 | MEDIUM | 6.1 | 12.2% | Jul 1, 2020 | An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected u... |
| CVE-2020-14196 | MEDIUM | 5.3 | 1.7% | Jul 1, 2020 | In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal we... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now