2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13597 | LOW | 3.5 | 0.9% | Jun 3, 2020 | Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to info... |
| CVE-2020-12846 | HIGH | 8 | 2.6% | Jun 3, 2020 | Zimbra before 8.8.15 Patch 10 and 9.x before 9.0.0 Patch 3 allows remote code execution via an avatar file. There is pot... |
| CVE-2020-4307 | MEDIUM | 6.5 | 0.5% | Jun 3, 2020 | IBM Security Guardium 11.1 could allow an attacker on the same network to gain access to the Solr dashboard and cause a ... |
| CVE-2020-4190 | MEDIUM | 6.7 | 0.2% | Jun 3, 2020 | IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, whi... |
| CVE-2020-4187 | MEDIUM | 5.3 | 1.1% | Jun 3, 2020 | IBM Security Guardium 11.1 could disclose sensitive information on the login page that could aid in further attacks agai... |
| CVE-2020-4182 | MEDIUM | 6.1 | 0.7% | Jun 3, 2020 | IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2020-4180 | HIGH | 8.8 | 3.0% | Jun 3, 2020 | IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By s... |
| CVE-2020-4177 | CRITICAL | 9.8 | 1.0% | Jun 3, 2020 | IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for i... |
| CVE-2020-1703 | — | — | — | Jun 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-13756 | CRITICAL | 9.8 | 55.1% | Jun 3, 2020 | Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the... |
| CVE-2020-13596 | MEDIUM | 6.1 | 2.9% | Jun 3, 2020 | An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin... |
| CVE-2020-13254 | MEDIUM | 5.9 | 6.0% | Jun 3, 2020 | An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not pe... |
| CVE-2020-10749 | MEDIUM | 6 | 2.4% | Jun 3, 2020 | A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious con... |
| CVE-2020-10516 | CRITICAL | 9.8 | 1.6% | Jun 3, 2020 | An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization... |
| CVE-2020-7117 | HIGH | 7.2 | 3.3% | Jun 3, 2020 | The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the atta... |
| CVE-2020-7116 | HIGH | 7.2 | 3.3% | Jun 3, 2020 | The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the atta... |
| CVE-2020-7115 | CRITICAL | 9.8 | 64.6% | Jun 3, 2020 | The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon succ... |
| CVE-2020-2200 | HIGH | 8.8 | 2.4% | Jun 3, 2020 | Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the `play` command on the Jenkins master ... |
| CVE-2020-2199 | MEDIUM | 6.1 | 6.2% | Jun 3, 2020 | Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository... |
| CVE-2020-2198 | MEDIUM | 6.5 | 0.8% | Jun 3, 2020 | Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API UR... |
| CVE-2020-2197 | MEDIUM | 4.3 | 0.6% | Jun 3, 2020 | Jenkins Project Inheritance Plugin 19.08.02 and earlier does not require users to have Job/ExtendedRead permission to ac... |
| CVE-2020-2196 | HIGH | 8 | 0.9% | Jun 3, 2020 | Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perfor... |
| CVE-2020-2195 | MEDIUM | 5.4 | 0.7% | Jun 3, 2020 | Jenkins Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips, resulting in a sto... |
| CVE-2020-2194 | MEDIUM | 5.4 | 0.7% | Jun 3, 2020 | Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the display name of the builds in the trend chart, result... |
| CVE-2020-2193 | MEDIUM | 5.4 | 0.7% | Jun 3, 2020 | Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the parser identifier when rendering charts, resulting in... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now