2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7733 | HIGH | 7.5 | 4.5% | Sep 16, 2020 | The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for ... |
| CVE-2020-2278 | MEDIUM | 6.5 | 1.4% | Sep 16, 2020 | Jenkins Storable Configs Plugin 1.0 and earlier does not restrict the user-specified file name, allowing attackers with ... |
| CVE-2020-2277 | MEDIUM | 6.5 | 1.7% | Sep 16, 2020 | Jenkins Storable Configs Plugin 1.0 and earlier allows users with Job/Read permission to read arbitrary files on the Jen... |
| CVE-2020-2276 | HIGH | 8.8 | 1.6% | Sep 16, 2020 | Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing att... |
| CVE-2020-2275 | MEDIUM | 6.5 | 1.7% | Sep 16, 2020 | Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins co... |
| CVE-2020-2274 | MEDIUM | 5.5 | 0.3% | Sep 16, 2020 | Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the... |
| CVE-2020-2273 | MEDIUM | 4.3 | 0.7% | Sep 16, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers to conne... |
| CVE-2020-2272 | MEDIUM | 4.3 | 0.7% | Sep 16, 2020 | A missing permission check in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers with Overall/Read permission to... |
| CVE-2020-2271 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Locked Files Report Plugin 1.6 and earlier does not escape locked files' names in tooltips, resulting in a store... |
| CVE-2020-2270 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins ClearCase Release Plugin 0.3 and earlier does not escape the composite baseline in badge tooltip, resulting in a... |
| CVE-2020-2269 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins chosen-views-tabbar Plugin 1.2 and earlier does not escape view names in the dropdown to select views, resulting... |
| CVE-2020-2268 | HIGH | 8.8 | 0.7% | Sep 16, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain acc... |
| CVE-2020-2267 | MEDIUM | 4.3 | 0.7% | Sep 16, 2020 | A missing permission check in Jenkins MongoDB Plugin 1.3 and earlier allows attackers with Overall/Read permission to ga... |
| CVE-2020-2266 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting i... |
| CVE-2020-2265 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, re... |
| CVE-2020-2264 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored c... |
| CVE-2020-2263 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Radiator View Plugin 1.29 and earlier does not escape the full name of the jobs in tooltips, resulting in a stor... |
| CVE-2020-2262 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cr... |
| CVE-2020-2261 | HIGH | 8.8 | 1.4% | Sep 16, 2020 | Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Confi... |
| CVE-2020-2260 | MEDIUM | 4.3 | 0.7% | Sep 16, 2020 | A missing permission check in Jenkins Perfecto Plugin 1.17 and earlier allows attackers with Overall/Read permission to ... |
| CVE-2020-2259 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored c... |
| CVE-2020-2258 | MEDIUM | 4.3 | 0.7% | Sep 16, 2020 | Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP en... |
| CVE-2020-2257 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Validating String Parameter Plugin 2.4 and earlier does not escape various user-controlled fields, resulting in ... |
| CVE-2020-2256 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as par... |
| CVE-2020-2255 | MEDIUM | 4.3 | 0.8% | Sep 16, 2020 | A missing permission check in Jenkins Blue Ocean Plugin 1.23.2 and earlier allows attackers with Overall/Read permission... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now