2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4280HIGH8.8IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecur...
CVE-2020-24301MEDIUM6.1Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability ...
CVE-2020-15646MEDIUM5.9If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange ...
CVE-2020-13344MEDIUM4.4An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are sto...
CVE-2020-13340HIGH8.7An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job ...
CVE-2020-13339MEDIUM6.5An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview...
CVE-2020-12401MEDIUM4.7During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication w...
CVE-2020-12400MEDIUM4.7When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulti...
CVE-2020-2298MEDIUM6.5Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attac...
CVE-2020-2297LOW3.3Jenkins SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file on t...
CVE-2020-2296MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to ...
CVE-2020-2295MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attac...
CVE-2020-2294MEDIUM6.5Jenkins Maven Cascade Release Plugin 1.3.2 and earlier does not perform permission checks in several HTTP endpoints, all...
CVE-2020-2293MEDIUM6.5Jenkins Persona Plugin 2.4 and earlier allows users with Overall/Read permission to read arbitrary files on the Jenkins ...
CVE-2020-2292MEDIUM5.4Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cr...
CVE-2020-2291LOW3.3Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration fil...
CVE-2020-2290MEDIUM5.4Jenkins Active Choices Plugin 2.4 and earlier does not escape some return values of sandboxed scripts for Reactive Refer...
CVE-2020-2289MEDIUM5.4Jenkins Active Choices Plugin 2.4 and earlier does not escape the name and description of build parameters, resulting in...
CVE-2020-2288MEDIUM5.3In Jenkins Audit Trail Plugin 3.6 and earlier, the default regular expression pattern could be bypassed in many cases by...
CVE-2020-2287MEDIUM5.3Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths t...
CVE-2020-2286HIGH8.8Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when th...
CVE-2020-26567MEDIUM5.5An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed ...
CVE-2020-25273CRITICAL9.8In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php v...
CVE-2020-25272MEDIUM6.1In SourceCodester Online Bus Booking System 1.0, there is XSS through the name parameter in book_now.php.
CVE-2020-25271MEDIUM5.4PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appoin...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now