2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2179 | HIGH | 8.8 | 2.9% | Apr 16, 2020 | Jenkins Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary ... |
| CVE-2020-2178 | HIGH | 7.1 | 0.9% | Apr 16, 2020 | Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XX... |
| CVE-2020-2177 | MEDIUM | 4.3 | 0.5% | Apr 16, 2020 | Jenkins Copr Plugin 0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where t... |
| CVE-2020-1964 | CRITICAL | 9.8 | 4.8% | Apr 16, 2020 | It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not ... |
| CVE-2020-11826 | HIGH | 7.5 | 0.5% | Apr 16, 2020 | Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. Ho... |
| CVE-2020-11825 | HIGH | 8.8 | 1.0% | Apr 16, 2020 | In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any use... |
| CVE-2020-11823 | MEDIUM | 5.4 | 0.7% | Apr 16, 2020 | In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit pag... |
| CVE-2020-11820 | CRITICAL | 9.8 | 1.8% | Apr 16, 2020 | Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the entities_id parameter... |
| CVE-2020-11819 | CRITICAL | 9.8 | 26.8% | Apr 16, 2020 | In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve... |
| CVE-2020-11818 | HIGH | 8.8 | 0.8% | Apr 16, 2020 | In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed w... |
| CVE-2020-11816 | CRITICAL | 9.8 | 1.8% | Apr 16, 2020 | Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the reports_id (POST) par... |
| CVE-2020-11815 | CRITICAL | 9.8 | 2.3% | Apr 16, 2020 | In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a re... |
| CVE-2020-11814 | MEDIUM | 5.4 | 1.0% | Apr 16, 2020 | A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users ... |
| CVE-2020-11813 | MEDIUM | 5.4 | 0.5% | Apr 16, 2020 | In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the configuration page via the copyright text input. Thus, ... |
| CVE-2020-11812 | CRITICAL | 9.8 | 1.7% | Apr 16, 2020 | Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the filters[0][value] or ... |
| CVE-2020-11811 | CRITICAL | 9.8 | 3.0% | Apr 16, 2020 | In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability w... |
| CVE-2020-11007 | MEDIUM | 6.5 | 0.9% | Apr 16, 2020 | In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated ... |
| CVE-2020-10707 | — | — | — | Apr 16, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-11612. Reason: This candidate is a reservation d... |
| CVE-2020-4347 | HIGH | 7.3 | 1.8% | Apr 16, 2020 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to ... |
| CVE-2020-4338 | MEDIUM | 5.5 | 0.3% | Apr 16, 2020 | IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras... |
| CVE-2020-4260 | MEDIUM | 4.3 | 0.9% | Apr 16, 2020 | IBM UrbanCode Deploy (UCD) 7.0.5 could allow a user with special permissions to obtain sensitive information via generic... |
| CVE-2020-3653 | CRITICAL | 9.1 | 0.9% | Apr 16, 2020 | Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from users... |
| CVE-2020-3652 | CRITICAL | 9.1 | 0.9% | Apr 16, 2020 | Possible buffer over-read issue in windows x86 wlan driver function while processing beacon or request frame due to lack... |
| CVE-2020-3651 | HIGH | 7.5 | 0.7% | Apr 16, 2020 | Active command timeout since WM status change cmd is not removed from active queue if peer sends multiple deauth frames.... |
| CVE-2020-9280 | HIGH | 7.5 | 1.7% | Apr 15, 2020 | In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the de... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now