2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-2125MEDIUM4.3Jenkins Debian Package Builder Plugin 1.6.11 and earlier stores a GPG passphrase unencrypted in its global configuration...
CVE-2020-2124MEDIUM4.3Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files...
CVE-2020-2122MEDIUM5.4Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resu...
CVE-2020-2119MEDIUM5.3Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins c...
CVE-2020-2118MEDIUM4.3A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allow...
CVE-2020-2117MEDIUM4.3A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall...
CVE-2020-2113MEDIUM5.4Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored...
CVE-2020-2112MEDIUM5.4Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a store...
CVE-2020-2111MEDIUM5.4Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field...
CVE-2020-8894MEDIUM6.5An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsCon...
CVE-2020-8891MEDIUM5.9An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force ser...
CVE-2020-8890MEDIUM5.9An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and ...
CVE-2020-0756MEDIUM5.5An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper...
CVE-2020-0755MEDIUM5.5An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper...
CVE-2020-0751MEDIUM6A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific mal...
CVE-2020-0748MEDIUM5.5An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper...
CVE-2020-0746MEDIUM5.5An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, a...
CVE-2020-0744MEDIUM5.5An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec...
CVE-2020-0736MEDIUM5.5An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window...
CVE-2020-0728MEDIUM5.5An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'W...
CVE-2020-0717MEDIUM5.5An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi...
CVE-2020-0716MEDIUM5.5An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi...
CVE-2020-0714MEDIUM5.5An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Informati...
CVE-2020-0706MEDIUM4.3An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests,...
CVE-2020-0705MEDIUM5.5An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now