2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-2315MEDIUM6.5Jenkins Visualworks Store Plugin 1.1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE...
CVE-2020-2314MEDIUM5.5Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkin...
CVE-2020-2313MEDIUM4.3A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permissi...
CVE-2020-2312MEDIUM6.5Jenkins SQLPlus Script Runner Plugin 2.0.12 and earlier does not mask a password provided as command line argument in bu...
CVE-2020-2311MEDIUM4.3A missing permission check in Jenkins AWS Global Configuration Plugin 1.5 and earlier allows attackers with Overall/Read...
CVE-2020-2310MEDIUM4.3Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enum...
CVE-2020-2309MEDIUM4.3A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Re...
CVE-2020-2308MEDIUM4.3A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission...
CVE-2020-2307MEDIUM4.3Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller ...
CVE-2020-2306MEDIUM4.3A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to...
CVE-2020-2305MEDIUM6.5Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks...
CVE-2020-2304MEDIUM6.5Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) atta...
CVE-2020-2303MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers t...
CVE-2020-2302MEDIUM4.3A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permis...
CVE-2020-2301CRITICAL9.8Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a succes...
CVE-2020-2300CRITICAL9.8Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, wh...
CVE-2020-2299CRITICAL9.8Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as t...
CVE-2020-27346Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-26211HIGH8.7In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use ...
CVE-2020-1909CRITICAL9.8A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.2...
CVE-2020-1908MEDIUM4.6Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could hav...
CVE-2020-26210HIGH8.7In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execut...
CVE-2020-4785MEDIUM5.4IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hi...
CVE-2020-4649MEDIUM4.3IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by...
CVE-2020-6557MEDIUM6.5Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform d...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now