2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-2211HIGH8.8Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the ins...
CVE-2020-2210MEDIUM4.3Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier transmits configured passwords in plain text as part of its glob...
CVE-2020-2209MEDIUM4.3Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenki...
CVE-2020-2208MEDIUM4.3Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master wh...
CVE-2020-2207MEDIUM6.1Jenkins VncViewer Plugin 1.7 and earlier does not escape a parameter value in the checkVncServ form validation endpoint,...
CVE-2020-2206MEDIUM6.1Jenkins VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoi...
CVE-2020-2205MEDIUM4.8Jenkins VncRecorder Plugin 1.25 and earlier does not escape a tool path in the `checkVncServ` form validation endpoint, ...
CVE-2020-2204MEDIUM5.4A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read perm...
CVE-2020-2203MEDIUM4.3A cross-site request forgery vulnerability in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers to con...
CVE-2020-2202MEDIUM4.3A missing permission check in Jenkins Fortify on Demand Plugin 6.0.0 and earlier in form-related methods allowed users w...
CVE-2020-2201MEDIUM5.4Jenkins Sonargraph Integration Plugin 3.0.0 and earlier does not escape the file path for the Log file field form valida...
CVE-2020-12119HIGH8.1Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value ...
CVE-2020-15503HIGH7.5LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_im...
CVE-2020-9498MEDIUM6.7Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual chann...
CVE-2020-9497MEDIUM4.4Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If ...
CVE-2020-7821CRITICAL9.8Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to ...
CVE-2020-7820CRITICAL9.8Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to ...
CVE-2020-5911HIGH7.3In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packag...
CVE-2020-5910HIGH7.5In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use ...
CVE-2020-5909MEDIUM5.4In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface...
CVE-2020-3282MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communicati...
CVE-2020-15502HIGH7.5The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web site...
CVE-2020-3402HIGH7.5A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could ...
CVE-2020-3391MEDIUM6.5A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view...
CVE-2020-3340MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now