2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2152 | MEDIUM | 6.1 | 1.2% | Mar 9, 2020 | Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field... |
| CVE-2020-2151 | MEDIUM | 5.3 | 0.7% | Mar 9, 2020 | Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkin... |
| CVE-2020-2150 | MEDIUM | 5.3 | 0.6% | Mar 9, 2020 | Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its globa... |
| CVE-2020-2149 | MEDIUM | 5.3 | 0.6% | Mar 9, 2020 | Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its glob... |
| CVE-2020-2148 | MEDIUM | 4.3 | 0.8% | Mar 9, 2020 | A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to conn... |
| CVE-2020-2147 | MEDIUM | 4.3 | 0.8% | Mar 9, 2020 | A cross-site request forgery vulnerability in Jenkins Mac Plugin 1.1.0 and earlier allows attackers to connect to an att... |
| CVE-2020-2145 | MEDIUM | 5.5 | 0.3% | Mar 9, 2020 | Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenki... |
| CVE-2020-2143 | MEDIUM | 5.3 | 0.6% | Mar 9, 2020 | Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins c... |
| CVE-2020-2142 | MEDIUM | 4.3 | 0.6% | Mar 9, 2020 | A missing permission check in Jenkins P4 Plugin 1.10.10 and earlier allows attackers with Overall/Read permission to tri... |
| CVE-2020-2141 | MEDIUM | 4.3 | 0.6% | Mar 9, 2020 | A cross-site request forgery vulnerability in Jenkins P4 Plugin 1.10.10 and earlier allows attackers to trigger builds o... |
| CVE-2020-2140 | MEDIUM | 6.1 | 76.0% | Mar 9, 2020 | Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation,... |
| CVE-2020-2139 | MEDIUM | 6.5 | 1.6% | Mar 9, 2020 | An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the ... |
| CVE-2020-2137 | MEDIUM | 4.8 | 0.7% | Mar 9, 2020 | Jenkins Timestamper Plugin 1.11.1 and earlier does not sanitize HTML formatting of its output, resulting in a stored XSS... |
| CVE-2020-2136 | MEDIUM | 5.4 | 0.9% | Mar 9, 2020 | Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field fo... |
| CVE-2020-10237 | MEDIUM | 5.5 | 0.2% | Mar 9, 2020 | An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords int... |
| CVE-2020-10236 | MEDIUM | 6.1 | 0.3% | Mar 9, 2020 | An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the... |
| CVE-2020-9282 | MEDIUM | 6.5 | 0.9% | Mar 9, 2020 | In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discover... |
| CVE-2020-9281 | MEDIUM | 6.1 | 4.3% | Mar 7, 2020 | A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attacke... |
| CVE-2020-8439 | MEDIUM | 6.5 | 1.6% | Mar 7, 2020 | Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login pa... |
| CVE-2020-10112 | MEDIUM | 5.4 | 1.4% | Mar 6, 2020 | Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By defaul... |
| CVE-2020-10110 | MEDIUM | 5.3 | 2.6% | Mar 6, 2020 | Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vul... |
| CVE-2020-9455 | MEDIUM | 4.3 | 1.4% | Mar 6, 2020 | The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) t... |
| CVE-2020-9530 | MEDIUM | 6.5 | 1.5% | Mar 6, 2020 | An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. The export component of GetApps(com.xiaomi.mipicks) mi... |
| CVE-2020-5405 | MEDIUM | 6.5 | 68.5% | Mar 5, 2020 | Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow ... |
| CVE-2020-4083 | MEDIUM | 5.5 | 0.3% | Mar 5, 2020 | HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now