2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2125 | MEDIUM | 4.3 | 0.7% | Feb 12, 2020 | Jenkins Debian Package Builder Plugin 1.6.11 and earlier stores a GPG passphrase unencrypted in its global configuration... |
| CVE-2020-2124 | MEDIUM | 4.3 | 0.7% | Feb 12, 2020 | Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files... |
| CVE-2020-2122 | MEDIUM | 5.4 | 0.8% | Feb 12, 2020 | Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resu... |
| CVE-2020-2119 | MEDIUM | 5.3 | 0.9% | Feb 12, 2020 | Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins c... |
| CVE-2020-2118 | MEDIUM | 4.3 | 0.7% | Feb 12, 2020 | A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allow... |
| CVE-2020-2117 | MEDIUM | 4.3 | 0.7% | Feb 12, 2020 | A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall... |
| CVE-2020-2113 | MEDIUM | 5.4 | 0.7% | Feb 12, 2020 | Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored... |
| CVE-2020-2112 | MEDIUM | 5.4 | 0.7% | Feb 12, 2020 | Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a store... |
| CVE-2020-2111 | MEDIUM | 5.4 | 0.9% | Feb 12, 2020 | Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field... |
| CVE-2020-8894 | MEDIUM | 6.5 | 1.4% | Feb 12, 2020 | An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsCon... |
| CVE-2020-8891 | MEDIUM | 5.9 | 1.4% | Feb 12, 2020 | An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force ser... |
| CVE-2020-8890 | MEDIUM | 5.9 | 1.1% | Feb 12, 2020 | An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and ... |
| CVE-2020-0756 | MEDIUM | 5.5 | 1.6% | Feb 11, 2020 | An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper... |
| CVE-2020-0755 | MEDIUM | 5.5 | 1.6% | Feb 11, 2020 | An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper... |
| CVE-2020-0751 | MEDIUM | 6 | 1.4% | Feb 11, 2020 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific mal... |
| CVE-2020-0748 | MEDIUM | 5.5 | 1.6% | Feb 11, 2020 | An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper... |
| CVE-2020-0746 | MEDIUM | 5.5 | 4.9% | Feb 11, 2020 | An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, a... |
| CVE-2020-0744 | MEDIUM | 5.5 | 1.9% | Feb 11, 2020 | An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec... |
| CVE-2020-0736 | MEDIUM | 5.5 | 1.5% | Feb 11, 2020 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window... |
| CVE-2020-0728 | MEDIUM | 5.5 | 3.7% | Feb 11, 2020 | An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'W... |
| CVE-2020-0717 | MEDIUM | 5.5 | 1.5% | Feb 11, 2020 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi... |
| CVE-2020-0716 | MEDIUM | 5.5 | 1.5% | Feb 11, 2020 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi... |
| CVE-2020-0714 | MEDIUM | 5.5 | 1.4% | Feb 11, 2020 | An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Informati... |
| CVE-2020-0706 | MEDIUM | 4.3 | 4.4% | Feb 11, 2020 | An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests,... |
| CVE-2020-0705 | MEDIUM | 5.5 | 1.5% | Feb 11, 2020 | An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now