2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2195 | MEDIUM | 5.4 | 0.7% | Jun 3, 2020 | Jenkins Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips, resulting in a sto... |
| CVE-2020-2194 | MEDIUM | 5.4 | 0.7% | Jun 3, 2020 | Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the display name of the builds in the trend chart, result... |
| CVE-2020-2193 | MEDIUM | 5.4 | 0.7% | Jun 3, 2020 | Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the parser identifier when rendering charts, resulting in... |
| CVE-2020-2192 | MEDIUM | 6.5 | 0.6% | Jun 3, 2020 | A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allo... |
| CVE-2020-2191 | MEDIUM | 4.3 | 0.7% | Jun 3, 2020 | Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier does not check permissions on API endpoints that a... |
| CVE-2020-2190 | MEDIUM | 5.4 | 0.8% | Jun 3, 2020 | Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the I... |
| CVE-2020-13776 | MEDIUM | 6.7 | 0.5% | Jun 3, 2020 | systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits... |
| CVE-2020-4026 | MEDIUM | 4.3 | 0.8% | Jun 3, 2020 | The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before v... |
| CVE-2020-13775 | MEDIUM | 6.5 | 1.8% | Jun 2, 2020 | ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) i... |
| CVE-2020-13762 | MEDIUM | 6.1 | 1.0% | Jun 2, 2020 | In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS. |
| CVE-2020-13761 | MEDIUM | 6.1 | 1.0% | Jun 2, 2020 | In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles... |
| CVE-2020-4503 | MEDIUM | 6.1 | 0.8% | Jun 2, 2020 | IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2020-4431 | MEDIUM | 5.4 | 0.6% | Jun 2, 2020 | IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2020-4366 | MEDIUM | 6.1 | 0.7% | Jun 2, 2020 | IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2020-4360 | MEDIUM | 5.4 | 0.7% | Jun 2, 2020 | IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2020-13754 | MEDIUM | 6.7 | 0.4% | Jun 2, 2020 | hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x m... |
| CVE-2020-13401 | MEDIUM | 6 | 2.8% | Jun 2, 2020 | An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, c... |
| CVE-2020-13228 | MEDIUM | 6.1 | 3.1% | Jun 2, 2020 | An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter. |
| CVE-2020-13227 | MEDIUM | 5.3 | 1.9% | Jun 2, 2020 | An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server i... |
| CVE-2020-10959 | MEDIUM | 6.1 | 1.4% | Jun 2, 2020 | resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and exter... |
| CVE-2020-10703 | MEDIUM | 6.5 | 2.4% | Jun 2, 2020 | A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in ... |
| CVE-2020-10136 | MEDIUM | 5.3 | 26.5% | Jun 2, 2020 | IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP tr... |
| CVE-2020-13758 | MEDIUM | 6.1 | 0.9% | Jun 1, 2020 | modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.... |
| CVE-2020-9071 | MEDIUM | 6.5 | 0.6% | Jun 1, 2020 | There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of t... |
| CVE-2020-12867 | MEDIUM | 5.5 | 0.5% | Jun 1, 2020 | A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now