2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24213 | HIGH | 7.5 | 1.1% | Sep 23, 2020 | An integer overflow was discovered in YGOPro ygocore v13.51. Attackers can use it to leak the game server thread's memor... |
| CVE-2020-4340 | MEDIUM | 4.3 | 0.7% | Sep 23, 2020 | IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate vali... |
| CVE-2020-4324 | MEDIUM | 4.3 | 1.2% | Sep 23, 2020 | IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improp... |
| CVE-2020-2285 | MEDIUM | 4.3 | 0.7% | Sep 23, 2020 | A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permi... |
| CVE-2020-2284 | HIGH | 7.1 | 0.9% | Sep 23, 2020 | Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE)... |
| CVE-2020-2283 | MEDIUM | 5.4 | 0.7% | Sep 23, 2020 | Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site s... |
| CVE-2020-2282 | MEDIUM | 4.3 | 0.7% | Sep 23, 2020 | Jenkins Implied Labels Plugin 0.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attacker... |
| CVE-2020-2281 | MEDIUM | 5.4 | 0.7% | Sep 23, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers ... |
| CVE-2020-2280 | HIGH | 8.8 | 1.1% | Sep 23, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Warnings Plugin 5.0.1 and earlier allows attackers to execu... |
| CVE-2020-2279 | CRITICAL | 9.9 | 2.1% | Sep 23, 2020 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to de... |
| CVE-2020-25739 | MEDIUM | 6.1 | 1.4% | Sep 23, 2020 | An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to ... |
| CVE-2020-16244 | HIGH | 7.2 | 0.7% | Sep 23, 2020 | GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible t... |
| CVE-2020-16240 | MEDIUM | 5.3 | 0.9% | Sep 23, 2020 | GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user acc... |
| CVE-2020-7122 | HIGH | 7.5 | 1.0% | Sep 23, 2020 | Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been ... |
| CVE-2020-7121 | HIGH | 7.5 | 1.0% | Sep 23, 2020 | Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been ... |
| CVE-2020-24626 | CRITICAL | 9.8 | 3.0% | Sep 23, 2020 | Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execut... |
| CVE-2020-24625 | HIGH | 7.5 | 1.6% | Sep 23, 2020 | Unathenticated directory traversal in the ReceiverServlet class doGet() method can lead to arbitrary file reads in HPE P... |
| CVE-2020-24624 | HIGH | 7.5 | 1.6% | Sep 23, 2020 | Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE... |
| CVE-2020-14370 | MEDIUM | 5.3 | 1.4% | Sep 23, 2020 | An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecat... |
| CVE-2020-14365 | HIGH | 7.1 | 0.2% | Sep 23, 2020 | A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, wh... |
| CVE-2020-10714 | HIGH | 7.5 | 1.5% | Sep 23, 2020 | A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with... |
| CVE-2020-10687 | MEDIUM | 4.8 | 1.1% | Sep 23, 2020 | A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to C... |
| CVE-2020-25826 | HIGH | 7.8 | 0.4% | Sep 23, 2020 | PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSub... |
| CVE-2020-25821 | HIGH | 7.5 | 1.4% | Sep 23, 2020 | peg-markdown 0.4.14 has a NULL pointer dereference in process_raw_blocks in markdown_lib.c. NOTE: This vulnerability onl... |
| CVE-2020-3569 | HIGH | 8.6 | 3.3% | Sep 23, 2020 | Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software coul... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now