2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13597LOW3.5Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to info...
CVE-2020-12846HIGH8Zimbra before 8.8.15 Patch 10 and 9.x before 9.0.0 Patch 3 allows remote code execution via an avatar file. There is pot...
CVE-2020-4307MEDIUM6.5IBM Security Guardium 11.1 could allow an attacker on the same network to gain access to the Solr dashboard and cause a ...
CVE-2020-4190MEDIUM6.7IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, whi...
CVE-2020-4187MEDIUM5.3IBM Security Guardium 11.1 could disclose sensitive information on the login page that could aid in further attacks agai...
CVE-2020-4182MEDIUM6.1IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2020-4180HIGH8.8IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By s...
CVE-2020-4177CRITICAL9.8IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for i...
CVE-2020-1703Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-13756CRITICAL9.8Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the...
CVE-2020-13596MEDIUM6.1An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin...
CVE-2020-13254MEDIUM5.9An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not pe...
CVE-2020-10749MEDIUM6A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious con...
CVE-2020-10516CRITICAL9.8An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization...
CVE-2020-7117HIGH7.2The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the atta...
CVE-2020-7116HIGH7.2The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the atta...
CVE-2020-7115CRITICAL9.8The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon succ...
CVE-2020-2200HIGH8.8Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the `play` command on the Jenkins master ...
CVE-2020-2199MEDIUM6.1Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository...
CVE-2020-2198MEDIUM6.5Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API UR...
CVE-2020-2197MEDIUM4.3Jenkins Project Inheritance Plugin 19.08.02 and earlier does not require users to have Job/ExtendedRead permission to ac...
CVE-2020-2196HIGH8Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perfor...
CVE-2020-2195MEDIUM5.4Jenkins Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips, resulting in a sto...
CVE-2020-2194MEDIUM5.4Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the display name of the builds in the trend chart, result...
CVE-2020-2193MEDIUM5.4Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the parser identifier when rendering charts, resulting in...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now