2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-2519MEDIUM4.3Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions...
CVE-2020-2515MEDIUM5Vulnerability in the Database Gateway for ODBC component of Oracle Database Server. Supported versions that are affected...
CVE-2020-2512MEDIUM5.9Vulnerability in the Database Gateway for ODBC component of Oracle Database Server. Supported versions that are affected...
CVE-2020-2096MEDIUM6.1Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a ref...
CVE-2020-2095MEDIUM4.3Jenkins Redgate SQL Change Automation Plugin 2.0.4 and earlier stored an API key unencrypted in job config.xml files on ...
CVE-2020-2094MEDIUM4.3A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/R...
CVE-2020-1611MEDIUM6.5A Local File Inclusion vulnerability in Juniper Networks Junos Space allows an attacker to view all files on the target ...
CVE-2020-1607MEDIUM6.1Insufficient Cross-Site Scripting (XSS) protection in J-Web may potentially allow a remote attacker to inject web script...
CVE-2020-1604MEDIUM5.3On EX4300, EX4600, QFX3500, and QFX5100 Series, a vulnerability in the IP firewall filter component may cause the firewa...
CVE-2020-1600MEDIUM6.5In a Point-to-Multipoint (P2MP) Label Switched Path (LSP) scenario, an uncontrolled resource consumption vulnerability i...
CVE-2020-5502MEDIUM6.5phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.
CVE-2020-5501MEDIUM4.3phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.
CVE-2020-0656MEDIUM5.4A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a speci...
CVE-2020-0647MEDIUM5.4A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, ak...
CVE-2020-0643MEDIUM5.5An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles...
CVE-2020-0639MEDIUM5.5An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to prop...
CVE-2020-0637MEDIUM6.5An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information,...
CVE-2020-0622MEDIUM5.5An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects ...
CVE-2020-0621MEDIUM4.4A security feature bypass vulnerability exists in Windows 10 when third party filters are called during a password updat...
CVE-2020-0617MEDIUM6A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate ...
CVE-2020-0616MEDIUM5.5A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Se...
CVE-2020-0615MEDIUM5.5An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to prop...
CVE-2020-0608MEDIUM5.5An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi...
CVE-2020-0607MEDIUM5.5An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, a...
CVE-2020-7057MEDIUM5.3Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessio...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now