2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4280 | HIGH | 8.8 | 73.5% | Oct 8, 2020 | IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecur... |
| CVE-2020-24301 | MEDIUM | 6.1 | 0.9% | Oct 8, 2020 | Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability ... |
| CVE-2020-15646 | MEDIUM | 5.9 | 0.9% | Oct 8, 2020 | If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange ... |
| CVE-2020-13344 | MEDIUM | 4.4 | 0.3% | Oct 8, 2020 | An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are sto... |
| CVE-2020-13340 | HIGH | 8.7 | 68.6% | Oct 8, 2020 | An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job ... |
| CVE-2020-13339 | MEDIUM | 6.5 | 0.8% | Oct 8, 2020 | An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview... |
| CVE-2020-12401 | MEDIUM | 4.7 | 0.3% | Oct 8, 2020 | During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication w... |
| CVE-2020-12400 | MEDIUM | 4.7 | 0.3% | Oct 8, 2020 | When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulti... |
| CVE-2020-2298 | MEDIUM | 6.5 | 1.1% | Oct 8, 2020 | Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attac... |
| CVE-2020-2297 | LOW | 3.3 | 0.3% | Oct 8, 2020 | Jenkins SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file on t... |
| CVE-2020-2296 | MEDIUM | 4.3 | 0.8% | Oct 8, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to ... |
| CVE-2020-2295 | MEDIUM | 6.5 | 0.5% | Oct 8, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attac... |
| CVE-2020-2294 | MEDIUM | 6.5 | 0.8% | Oct 8, 2020 | Jenkins Maven Cascade Release Plugin 1.3.2 and earlier does not perform permission checks in several HTTP endpoints, all... |
| CVE-2020-2293 | MEDIUM | 6.5 | 1.0% | Oct 8, 2020 | Jenkins Persona Plugin 2.4 and earlier allows users with Overall/Read permission to read arbitrary files on the Jenkins ... |
| CVE-2020-2292 | MEDIUM | 5.4 | 0.7% | Oct 8, 2020 | Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cr... |
| CVE-2020-2291 | LOW | 3.3 | 0.3% | Oct 8, 2020 | Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration fil... |
| CVE-2020-2290 | MEDIUM | 5.4 | 0.9% | Oct 8, 2020 | Jenkins Active Choices Plugin 2.4 and earlier does not escape some return values of sandboxed scripts for Reactive Refer... |
| CVE-2020-2289 | MEDIUM | 5.4 | 0.9% | Oct 8, 2020 | Jenkins Active Choices Plugin 2.4 and earlier does not escape the name and description of build parameters, resulting in... |
| CVE-2020-2288 | MEDIUM | 5.3 | 0.9% | Oct 8, 2020 | In Jenkins Audit Trail Plugin 3.6 and earlier, the default regular expression pattern could be bypassed in many cases by... |
| CVE-2020-2287 | MEDIUM | 5.3 | 1.2% | Oct 8, 2020 | Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths t... |
| CVE-2020-2286 | HIGH | 8.8 | 1.3% | Oct 8, 2020 | Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when th... |
| CVE-2020-26567 | MEDIUM | 5.5 | 17.2% | Oct 8, 2020 | An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed ... |
| CVE-2020-25273 | CRITICAL | 9.8 | 1.8% | Oct 8, 2020 | In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php v... |
| CVE-2020-25272 | MEDIUM | 6.1 | 0.9% | Oct 8, 2020 | In SourceCodester Online Bus Booking System 1.0, there is XSS through the name parameter in book_now.php. |
| CVE-2020-25271 | MEDIUM | 5.4 | 0.6% | Oct 8, 2020 | PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appoin... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now