2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2211 | HIGH | 8.8 | 2.3% | Jul 2, 2020 | Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the ins... |
| CVE-2020-2210 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier transmits configured passwords in plain text as part of its glob... |
| CVE-2020-2209 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenki... |
| CVE-2020-2208 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master wh... |
| CVE-2020-2207 | MEDIUM | 6.1 | 0.9% | Jul 2, 2020 | Jenkins VncViewer Plugin 1.7 and earlier does not escape a parameter value in the checkVncServ form validation endpoint,... |
| CVE-2020-2206 | MEDIUM | 6.1 | 0.9% | Jul 2, 2020 | Jenkins VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoi... |
| CVE-2020-2205 | MEDIUM | 4.8 | 0.7% | Jul 2, 2020 | Jenkins VncRecorder Plugin 1.25 and earlier does not escape a tool path in the `checkVncServ` form validation endpoint, ... |
| CVE-2020-2204 | MEDIUM | 5.4 | 0.6% | Jul 2, 2020 | A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read perm... |
| CVE-2020-2203 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | A cross-site request forgery vulnerability in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers to con... |
| CVE-2020-2202 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | A missing permission check in Jenkins Fortify on Demand Plugin 6.0.0 and earlier in form-related methods allowed users w... |
| CVE-2020-2201 | MEDIUM | 5.4 | 0.7% | Jul 2, 2020 | Jenkins Sonargraph Integration Plugin 3.0.0 and earlier does not escape the file path for the Log file field form valida... |
| CVE-2020-12119 | HIGH | 8.1 | 0.5% | Jul 2, 2020 | Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value ... |
| CVE-2020-15503 | HIGH | 7.5 | 3.7% | Jul 2, 2020 | LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_im... |
| CVE-2020-9498 | MEDIUM | 6.7 | 0.7% | Jul 2, 2020 | Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual chann... |
| CVE-2020-9497 | MEDIUM | 4.4 | 0.8% | Jul 2, 2020 | Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If ... |
| CVE-2020-7821 | CRITICAL | 9.8 | 1.6% | Jul 2, 2020 | Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to ... |
| CVE-2020-7820 | CRITICAL | 9.8 | 1.6% | Jul 2, 2020 | Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to ... |
| CVE-2020-5911 | HIGH | 7.3 | 1.0% | Jul 2, 2020 | In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packag... |
| CVE-2020-5910 | HIGH | 7.5 | 1.2% | Jul 2, 2020 | In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use ... |
| CVE-2020-5909 | MEDIUM | 5.4 | 0.4% | Jul 2, 2020 | In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface... |
| CVE-2020-3282 | MEDIUM | 6.1 | 0.8% | Jul 2, 2020 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communicati... |
| CVE-2020-15502 | HIGH | 7.5 | 1.5% | Jul 2, 2020 | The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web site... |
| CVE-2020-3402 | HIGH | 7.5 | 1.6% | Jul 2, 2020 | A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could ... |
| CVE-2020-3391 | MEDIUM | 6.5 | 1.3% | Jul 2, 2020 | A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view... |
| CVE-2020-3340 | MEDIUM | 4.8 | 0.6% | Jul 2, 2020 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now