2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-2233MEDIUM6.5A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read...
CVE-2020-2232HIGH7.5Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the globa...
CVE-2020-2231MEDIUM5.4Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via '...
CVE-2020-2230MEDIUM5.4Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in...
CVE-2020-2229MEDIUM5.4Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a sto...
CVE-2020-17496CRITICAL9.8vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe...
CVE-2020-13278MEDIUM6.1Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remo...
CVE-2020-6932CRITICAL9.8An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Softwa...
CVE-2020-17373MEDIUM5.3SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection.
CVE-2020-17372MEDIUM5.4SugarCRM before 10.1.0 (Q3 2020) allows XSS.
CVE-2020-16266MEDIUM5.4An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attack...
CVE-2020-16145MEDIUM6.1Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG do...
CVE-2020-8913HIGH8.8A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Librar...
CVE-2020-7029HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Ava...
CVE-2020-17495HIGH7.5django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables pass...
CVE-2020-17489MEDIUM4.3An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, t...
CVE-2020-8912LOW2.5A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attac...
CVE-2020-8911MEDIUM5.6A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to ...
CVE-2020-17487HIGH7.5radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentif...
CVE-2020-16170HIGH7.5Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to ...
CVE-2020-0260CRITICAL9.1There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID:...
CVE-2020-0259HIGH7.8In android_verity_ctr of dm-android-verity.c, there is a possible way to modify a dm-verity protected filesystem due to ...
CVE-2020-0258MEDIUM5.5In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local information disclosure...
CVE-2020-0257HIGH7.8In SpecializeCommon of com_android_internal_os_Zygote.cpp, there is a permissions bypass due to an incomplete cleanup. T...
CVE-2020-0256MEDIUM6.8In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This could lead ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now