2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2254 | MEDIUM | 6.5 | 2.1% | Sep 16, 2020 | Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacke... |
| CVE-2020-2253 | MEDIUM | 4.8 | 0.7% | Sep 16, 2020 | Jenkins Email Extension Plugin 2.75 and earlier does not perform hostname validation when connecting to the configured S... |
| CVE-2020-2252 | MEDIUM | 4.8 | 1.0% | Sep 16, 2020 | Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP serve... |
| CVE-2020-25412 | CRITICAL | 9.8 | 2.5% | Sep 16, 2020 | com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code ex... |
| CVE-2020-14393 | HIGH | 7.1 | 0.6% | Sep 16, 2020 | A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 3... |
| CVE-2020-14315 | CRITICAL | 9.8 | 2.5% | Sep 16, 2020 | A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insuffi... |
| CVE-2020-25559 | HIGH | 7.8 | 1.6% | Sep 16, 2020 | gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary c... |
| CVE-2020-14392 | MEDIUM | 5.5 | 0.6% | Sep 16, 2020 | An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to... |
| CVE-2020-14386 | HIGH | 7.8 | 1.3% | Sep 16, 2020 | A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unp... |
| CVE-2020-10781 | MEDIUM | 5.5 | 0.3% | Sep 16, 2020 | A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the... |
| CVE-2020-7268 | MEDIUM | 4.3 | 1.0% | Sep 16, 2020 | Path Traversal vulnerability in McAfee McAfee Email Gateway (MEG) prior to 7.6.406 allows remote attackers to traverse t... |
| CVE-2020-7297 | MEDIUM | 5.7 | 0.4% | Sep 16, 2020 | Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user t... |
| CVE-2020-10768 | MEDIUM | 5.5 | 0.4% | Sep 16, 2020 | A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect bra... |
| CVE-2020-7296 | MEDIUM | 5.7 | 0.4% | Sep 15, 2020 | Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user t... |
| CVE-2020-7295 | MEDIUM | 4.6 | 0.5% | Sep 15, 2020 | Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user t... |
| CVE-2020-7294 | MEDIUM | 4.6 | 0.4% | Sep 15, 2020 | Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user t... |
| CVE-2020-7293 | CRITICAL | 9 | 0.7% | Sep 15, 2020 | Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user w... |
| CVE-2020-10767 | MEDIUM | 5.5 | 0.4% | Sep 15, 2020 | A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Predicti... |
| CVE-2020-10766 | MEDIUM | 5.5 | 0.5% | Sep 15, 2020 | A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling all... |
| CVE-2020-25453 | HIGH | 8.8 | 6.3% | Sep 15, 2020 | An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote... |
| CVE-2020-23833 | CRITICAL | 9.8 | 4.2% | Sep 15, 2020 | Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers t... |
| CVE-2020-23828 | CRITICAL | 9.8 | 4.1% | Sep 15, 2020 | A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote ... |
| CVE-2020-14385 | MEDIUM | 5.5 | 0.4% | Sep 15, 2020 | A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an... |
| CVE-2020-24561 | CRITICAL | 9.1 | 5.2% | Sep 15, 2020 | A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrar... |
| CVE-2020-14314 | MEDIUM | 5.5 | 0.4% | Sep 15, 2020 | A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now