2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-2195MEDIUM5.4Jenkins Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips, resulting in a sto...
CVE-2020-2194MEDIUM5.4Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the display name of the builds in the trend chart, result...
CVE-2020-2193MEDIUM5.4Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the parser identifier when rendering charts, resulting in...
CVE-2020-2192MEDIUM6.5A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allo...
CVE-2020-2191MEDIUM4.3Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier does not check permissions on API endpoints that a...
CVE-2020-2190MEDIUM5.4Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the I...
CVE-2020-13776MEDIUM6.7systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits...
CVE-2020-4026MEDIUM4.3The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before v...
CVE-2020-13775MEDIUM6.5ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) i...
CVE-2020-13762MEDIUM6.1In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
CVE-2020-13761MEDIUM6.1In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles...
CVE-2020-4503MEDIUM6.1IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-4431MEDIUM5.4IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-4366MEDIUM6.1IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-4360MEDIUM5.4IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2020-13754MEDIUM6.7hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x m...
CVE-2020-13401MEDIUM6An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, c...
CVE-2020-13228MEDIUM6.1An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.
CVE-2020-13227MEDIUM5.3An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server i...
CVE-2020-10959MEDIUM6.1resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and exter...
CVE-2020-10703MEDIUM6.5A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in ...
CVE-2020-10136MEDIUM5.3IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP tr...
CVE-2020-13758MEDIUM6.1modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20....
CVE-2020-9071MEDIUM6.5There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of t...
CVE-2020-12867MEDIUM5.5A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now