2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-2179HIGH8.8Jenkins Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary ...
CVE-2020-2178HIGH7.1Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XX...
CVE-2020-2177MEDIUM4.3Jenkins Copr Plugin 0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where t...
CVE-2020-1964CRITICAL9.8It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not ...
CVE-2020-11826HIGH7.5Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. Ho...
CVE-2020-11825HIGH8.8In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any use...
CVE-2020-11823MEDIUM5.4In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit pag...
CVE-2020-11820CRITICAL9.8Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the entities_id parameter...
CVE-2020-11819CRITICAL9.8In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve...
CVE-2020-11818HIGH8.8In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed w...
CVE-2020-11816CRITICAL9.8Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the reports_id (POST) par...
CVE-2020-11815CRITICAL9.8In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a re...
CVE-2020-11814MEDIUM5.4A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users ...
CVE-2020-11813MEDIUM5.4In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the configuration page via the copyright text input. Thus, ...
CVE-2020-11812CRITICAL9.8Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the filters[0][value] or ...
CVE-2020-11811CRITICAL9.8In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability w...
CVE-2020-11007MEDIUM6.5In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated ...
CVE-2020-10707Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-11612. Reason: This candidate is a reservation d...
CVE-2020-4347HIGH7.3IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to ...
CVE-2020-4338MEDIUM5.5IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras...
CVE-2020-4260MEDIUM4.3IBM UrbanCode Deploy (UCD) 7.0.5 could allow a user with special permissions to obtain sensitive information via generic...
CVE-2020-3653CRITICAL9.1Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from users...
CVE-2020-3652CRITICAL9.1Possible buffer over-read issue in windows x86 wlan driver function while processing beacon or request frame due to lack...
CVE-2020-3651HIGH7.5Active command timeout since WM status change cmd is not removed from active queue if peer sends multiple deauth frames....
CVE-2020-9280HIGH7.5In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the de...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now