2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3246 | MEDIUM | 4.3 | 0.9% | May 6, 2020 | A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to perform a carriag... |
| CVE-2020-3188 | MEDIUM | 5.3 | 1.7% | May 6, 2020 | A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections... |
| CVE-2020-3186 | MEDIUM | 5.3 | 1.3% | May 6, 2020 | A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow... |
| CVE-2020-3178 | MEDIUM | 6.1 | 0.8% | May 6, 2020 | Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance ... |
| CVE-2020-7921 | MEDIUM | 5.3 | 0.7% | May 6, 2020 | Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem perm... |
| CVE-2020-12108 | MEDIUM | 6.5 | 2.7% | May 6, 2020 | /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection. |
| CVE-2020-6861 | MEDIUM | 5.5 | 0.4% | May 6, 2020 | A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attac... |
| CVE-2020-4446 | MEDIUM | 4.3 | 0.9% | May 6, 2020 | IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote a... |
| CVE-2020-4421 | MEDIUM | 5.4 | 0.7% | May 6, 2020 | IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spo... |
| CVE-2020-4384 | MEDIUM | 5.4 | 0.6% | May 6, 2020 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2020-10693 | MEDIUM | 5.3 | 2.3% | May 6, 2020 | A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invali... |
| CVE-2020-4092 | MEDIUM | 5.3 | 0.3% | May 6, 2020 | "If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clea... |
| CVE-2020-2188 | MEDIUM | 4.3 | 0.6% | May 6, 2020 | A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Ov... |
| CVE-2020-2187 | MEDIUM | 5.6 | 0.4% | May 6, 2020 | Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostn... |
| CVE-2020-2186 | MEDIUM | 4.3 | 0.6% | May 6, 2020 | A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision... |
| CVE-2020-2185 | MEDIUM | 5.6 | 0.7% | May 6, 2020 | Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the... |
| CVE-2020-2184 | MEDIUM | 4.3 | 44.5% | May 6, 2020 | A cross-site request forgery vulnerability in Jenkins CVS Plugin 2.15 and earlier allows attackers to create and manipul... |
| CVE-2020-2183 | MEDIUM | 6.5 | 0.9% | May 6, 2020 | Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifact... |
| CVE-2020-2182 | MEDIUM | 4.3 | 0.9% | May 6, 2020 | Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$... |
| CVE-2020-2181 | MEDIUM | 6.5 | 1.1% | May 6, 2020 | Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build lo... |
| CVE-2020-12666 | MEDIUM | 6.1 | 1.4% | May 5, 2020 | macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.c... |
| CVE-2020-12439 | MEDIUM | 5.3 | 1.6% | May 5, 2020 | Grin before 3.1.0 allows attackers to adversely affect availability of data on a Mimblewimble blockchain. |
| CVE-2020-11036 | MEDIUM | 5.4 | 0.8% | May 5, 2020 | In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored ... |
| CVE-2020-11034 | MEDIUM | 6.1 | 7.6% | May 5, 2020 | In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is... |
| CVE-2020-11051 | MEDIUM | 4.8 | 0.6% | May 5, 2020 | In Wiki.js before 2.3.81, there is a stored XSS in the Markdown editor. An editor with write access to a page, using the... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now