2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-3246MEDIUM4.3A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to perform a carriag...
CVE-2020-3188MEDIUM5.3A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections...
CVE-2020-3186MEDIUM5.3A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow...
CVE-2020-3178MEDIUM6.1Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance ...
CVE-2020-7921MEDIUM5.3Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem perm...
CVE-2020-12108MEDIUM6.5/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
CVE-2020-6861MEDIUM5.5A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attac...
CVE-2020-4446MEDIUM4.3IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote a...
CVE-2020-4421MEDIUM5.4IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spo...
CVE-2020-4384MEDIUM5.4IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2020-10693MEDIUM5.3A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invali...
CVE-2020-4092MEDIUM5.3"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clea...
CVE-2020-2188MEDIUM4.3A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Ov...
CVE-2020-2187MEDIUM5.6Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostn...
CVE-2020-2186MEDIUM4.3A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision...
CVE-2020-2185MEDIUM5.6Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the...
CVE-2020-2184MEDIUM4.3A cross-site request forgery vulnerability in Jenkins CVS Plugin 2.15 and earlier allows attackers to create and manipul...
CVE-2020-2183MEDIUM6.5Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifact...
CVE-2020-2182MEDIUM4.3Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$...
CVE-2020-2181MEDIUM6.5Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build lo...
CVE-2020-12666MEDIUM6.1macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.c...
CVE-2020-12439MEDIUM5.3Grin before 3.1.0 allows attackers to adversely affect availability of data on a Mimblewimble blockchain.
CVE-2020-11036MEDIUM5.4In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored ...
CVE-2020-11034MEDIUM6.1In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is...
CVE-2020-11051MEDIUM4.8In Wiki.js before 2.3.81, there is a stored XSS in the Markdown editor. An editor with write access to a page, using the...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now