2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-2192MEDIUM6.5A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allo...
CVE-2020-2191MEDIUM4.3Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier does not check permissions on API endpoints that a...
CVE-2020-2190MEDIUM5.4Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the I...
CVE-2020-1963CRITICAL9.1Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used ...
CVE-2020-13776MEDIUM6.7systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits...
CVE-2020-4026MEDIUM4.3The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before v...
CVE-2020-13775MEDIUM6.5ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) i...
CVE-2020-13764HIGH7.5common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not con...
CVE-2020-12607HIGH7.5An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the poin...
CVE-2020-13763HIGH7.5In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest...
CVE-2020-13762MEDIUM6.1In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
CVE-2020-13761MEDIUM6.1In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles...
CVE-2020-13760HIGH8.8In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
CVE-2020-7663HIGH7.5websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension par...
CVE-2020-7662HIGH7.5websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension pars...
CVE-2020-13759HIGH7.5rust-vmm vm-memory before 0.1.1 and 0.2.x before 0.2.1 allows attackers to cause a denial of service (loss of IP network...
CVE-2020-12017CRITICAL9.8GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerab...
CVE-2020-5410HIGH7.5Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow ...
CVE-2020-3680HIGH7A race condition can occur when using the fastrpc memory mapping API. in Snapdragon Auto, Snapdragon Compute, Snapdragon...
CVE-2020-3645HIGH7.5Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes...
CVE-2020-3641CRITICAL9.8Integer overflow may occur if atom size is less than atom offset as there is improper validation of atom size in Snapdra...
CVE-2020-3633CRITICAL9.8Array out of bound may occur while playing mp3 file as no check is there on offset if it is greater than the buffer allo...
CVE-2020-3630HIGH7.8Possibility of out of bound access while processing the responses from video firmware in Snapdragon Auto, Snapdragon Com...
CVE-2020-3625HIGH7.8When making query to DSP capabilities, Stack out of bounds occurs due to wrong buffer length configured for DSP attribut...
CVE-2020-3623HIGH7.8kernel failure due to load failures while running v1 path directly via kernel in Snapdragon Mobile in SM8250, SXR2130

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now