2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8947 | HIGH | 7.2 | 22.5% | Feb 12, 2020 | functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metac... |
| CVE-2020-8946 | HIGH | 8.8 | 1.9% | Feb 12, 2020 | Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacter... |
| CVE-2020-8945 | HIGH | 7.5 | 5.1% | Feb 12, 2020 | The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container ... |
| CVE-2020-7957 | MEDIUM | 5.3 | 1.8% | Feb 12, 2020 | The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be r... |
| CVE-2020-7046 | HIGH | 7.5 | 50.4% | Feb 12, 2020 | lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command paramet... |
| CVE-2020-8839 | MEDIUM | 6.1 | 2.1% | Feb 12, 2020 | Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cg... |
| CVE-2020-8815 | HIGH | 7.5 | 2.2% | Feb 12, 2020 | Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to ... |
| CVE-2020-8595 | HIGH | 7.3 | 2.6% | Feb 12, 2020 | Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. Th... |
| CVE-2020-2133 | MEDIUM | 6.5 | 0.9% | Feb 12, 2020 | Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master wher... |
| CVE-2020-2132 | MEDIUM | 6.5 | 0.9% | Feb 12, 2020 | Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on th... |
| CVE-2020-2131 | MEDIUM | 6.5 | 0.9% | Feb 12, 2020 | Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master ... |
| CVE-2020-2130 | MEDIUM | 6.5 | 0.9% | Feb 12, 2020 | Jenkins Harvest SCM Plugin 0.5.1 and earlier stores a password unencrypted in its global configuration file on the Jenki... |
| CVE-2020-2129 | MEDIUM | 6.5 | 0.9% | Feb 12, 2020 | Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenk... |
| CVE-2020-2128 | MEDIUM | 4.3 | 0.7% | Feb 12, 2020 | Jenkins ECX Copy Data Management Plugin 1.9 and earlier stores a password unencrypted in job config.xml files on the Jen... |
| CVE-2020-2127 | MEDIUM | 4.3 | 0.7% | Feb 12, 2020 | Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configura... |
| CVE-2020-2126 | MEDIUM | 4.3 | 0.7% | Feb 12, 2020 | Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins mast... |
| CVE-2020-2125 | MEDIUM | 4.3 | 0.7% | Feb 12, 2020 | Jenkins Debian Package Builder Plugin 1.6.11 and earlier stores a GPG passphrase unencrypted in its global configuration... |
| CVE-2020-2124 | MEDIUM | 4.3 | 0.7% | Feb 12, 2020 | Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files... |
| CVE-2020-2123 | HIGH | 8.8 | 2.3% | Feb 12, 2020 | Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary typ... |
| CVE-2020-2122 | MEDIUM | 5.4 | 0.8% | Feb 12, 2020 | Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resu... |
| CVE-2020-2121 | HIGH | 8.8 | 2.7% | Feb 12, 2020 | Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiatio... |
| CVE-2020-2120 | HIGH | 8.8 | 1.1% | Feb 12, 2020 | Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2020-2119 | MEDIUM | 5.3 | 0.9% | Feb 12, 2020 | Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins c... |
| CVE-2020-2118 | MEDIUM | 4.3 | 0.7% | Feb 12, 2020 | A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allow... |
| CVE-2020-2117 | MEDIUM | 4.3 | 0.7% | Feb 12, 2020 | A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now