2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2315 | MEDIUM | 6.5 | 1.1% | Nov 4, 2020 | Jenkins Visualworks Store Plugin 1.1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE... |
| CVE-2020-2314 | MEDIUM | 5.5 | 0.3% | Nov 4, 2020 | Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkin... |
| CVE-2020-2313 | MEDIUM | 4.3 | 0.8% | Nov 4, 2020 | A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permissi... |
| CVE-2020-2312 | MEDIUM | 6.5 | 1.0% | Nov 4, 2020 | Jenkins SQLPlus Script Runner Plugin 2.0.12 and earlier does not mask a password provided as command line argument in bu... |
| CVE-2020-2311 | MEDIUM | 4.3 | 0.8% | Nov 4, 2020 | A missing permission check in Jenkins AWS Global Configuration Plugin 1.5 and earlier allows attackers with Overall/Read... |
| CVE-2020-2310 | MEDIUM | 4.3 | 0.8% | Nov 4, 2020 | Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enum... |
| CVE-2020-2309 | MEDIUM | 4.3 | 1.1% | Nov 4, 2020 | A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Re... |
| CVE-2020-2308 | MEDIUM | 4.3 | 1.1% | Nov 4, 2020 | A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission... |
| CVE-2020-2307 | MEDIUM | 4.3 | 1.2% | Nov 4, 2020 | Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller ... |
| CVE-2020-2306 | MEDIUM | 4.3 | 1.1% | Nov 4, 2020 | A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to... |
| CVE-2020-2305 | MEDIUM | 6.5 | 1.4% | Nov 4, 2020 | Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks... |
| CVE-2020-2304 | MEDIUM | 6.5 | 1.5% | Nov 4, 2020 | Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) atta... |
| CVE-2020-2303 | MEDIUM | 4.3 | 0.7% | Nov 4, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers t... |
| CVE-2020-2302 | MEDIUM | 4.3 | 0.7% | Nov 4, 2020 | A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permis... |
| CVE-2020-2301 | CRITICAL | 9.8 | 1.7% | Nov 4, 2020 | Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a succes... |
| CVE-2020-2300 | CRITICAL | 9.8 | 1.7% | Nov 4, 2020 | Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, wh... |
| CVE-2020-2299 | CRITICAL | 9.8 | 1.3% | Nov 4, 2020 | Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as t... |
| CVE-2020-27346 | — | — | — | Nov 4, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-26211 | HIGH | 8.7 | 1.1% | Nov 3, 2020 | In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use ... |
| CVE-2020-1909 | CRITICAL | 9.8 | 2.2% | Nov 3, 2020 | A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.2... |
| CVE-2020-1908 | MEDIUM | 4.6 | 0.3% | Nov 3, 2020 | Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could hav... |
| CVE-2020-26210 | HIGH | 8.7 | 1.2% | Nov 3, 2020 | In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execut... |
| CVE-2020-4785 | MEDIUM | 5.4 | 0.7% | Nov 3, 2020 | IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hi... |
| CVE-2020-4649 | MEDIUM | 4.3 | 0.8% | Nov 3, 2020 | IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by... |
| CVE-2020-6557 | MEDIUM | 6.5 | 1.5% | Nov 3, 2020 | Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform d... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now