2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6129HIGH8.8SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_perio...
CVE-2020-6123HIGH8.8An exploitable sql injection vulnerability exists in the email parameter functionality of OS4Ed openSIS 7.3. The email p...
CVE-2020-6122HIGH8.8SQL injection vulnerability exists in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The mn parameter in the p...
CVE-2020-6121HIGH8.8SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The ln parameter in the ...
CVE-2020-6120HIGH8.8SQL injection vulnerability exists in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The fn parameter in the p...
CVE-2020-6119HIGH8.8SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The byear parameter in t...
CVE-2020-6118HIGH8.8SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The bmonth parameter in ...
CVE-2020-6117HIGH8.8SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The bday parameter in th...
CVE-2020-2251MEDIUM4.3Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain t...
CVE-2020-2250MEDIUM6.5Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml file...
CVE-2020-2249LOW3.3Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuratio...
CVE-2020-2248MEDIUM6.1Jenkins JSGames Plugin 0.2 and earlier evaluates part of a URL as code, resulting in a reflected cross-site scripting (X...
CVE-2020-2247MEDIUM6.5Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (...
CVE-2020-2246MEDIUM5.4Jenkins Valgrind Plugin 0.28 and earlier does not escape content in Valgrind XML reports, resulting in a stored cross-si...
CVE-2020-2245HIGH7.1Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2244MEDIUM5.4Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, re...
CVE-2020-2243MEDIUM5.4Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips, resulting in a stored ...
CVE-2020-2242MEDIUM6.5A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenki...
CVE-2020-2241HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect...
CVE-2020-2240HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to execute...
CVE-2020-2239MEDIUM4.3Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration fi...
CVE-2020-2238MEDIUM5.4Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page...
CVE-2020-24554HIGH7.5The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is re...
CVE-2020-14514MEDIUM4.3All trailer Power Line Communications are affected. PLC bus traffic can be sniffed reliably via an active antenna up to ...
CVE-2020-24584HIGH7.5An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used)....

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now