2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-24213HIGH7.5An integer overflow was discovered in YGOPro ygocore v13.51. Attackers can use it to leak the game server thread's memor...
CVE-2020-4340MEDIUM4.3IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate vali...
CVE-2020-4324MEDIUM4.3IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improp...
CVE-2020-2285MEDIUM4.3A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permi...
CVE-2020-2284HIGH7.1Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE)...
CVE-2020-2283MEDIUM5.4Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site s...
CVE-2020-2282MEDIUM4.3Jenkins Implied Labels Plugin 0.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attacker...
CVE-2020-2281MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers ...
CVE-2020-2280HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Warnings Plugin 5.0.1 and earlier allows attackers to execu...
CVE-2020-2279CRITICAL9.9A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to de...
CVE-2020-25739MEDIUM6.1An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to ...
CVE-2020-16244HIGH7.2GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible t...
CVE-2020-16240MEDIUM5.3GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user acc...
CVE-2020-7122HIGH7.5Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been ...
CVE-2020-7121HIGH7.5Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been ...
CVE-2020-24626CRITICAL9.8Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execut...
CVE-2020-24625HIGH7.5Unathenticated directory traversal in the ReceiverServlet class doGet() method can lead to arbitrary file reads in HPE P...
CVE-2020-24624HIGH7.5Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE...
CVE-2020-14370MEDIUM5.3An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecat...
CVE-2020-14365HIGH7.1A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, wh...
CVE-2020-10714HIGH7.5A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with...
CVE-2020-10687MEDIUM4.8A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to C...
CVE-2020-25826HIGH7.8PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSub...
CVE-2020-25821HIGH7.5peg-markdown 0.4.14 has a NULL pointer dereference in process_raw_blocks in markdown_lib.c. NOTE: This vulnerability onl...
CVE-2020-3569HIGH8.6Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software coul...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now