2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8947HIGH7.2functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metac...
CVE-2020-8946HIGH8.8Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacter...
CVE-2020-8945HIGH7.5The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container ...
CVE-2020-7957MEDIUM5.3The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be r...
CVE-2020-7046HIGH7.5lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command paramet...
CVE-2020-8839MEDIUM6.1Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cg...
CVE-2020-8815HIGH7.5Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to ...
CVE-2020-8595HIGH7.3Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. Th...
CVE-2020-2133MEDIUM6.5Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master wher...
CVE-2020-2132MEDIUM6.5Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on th...
CVE-2020-2131MEDIUM6.5Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master ...
CVE-2020-2130MEDIUM6.5Jenkins Harvest SCM Plugin 0.5.1 and earlier stores a password unencrypted in its global configuration file on the Jenki...
CVE-2020-2129MEDIUM6.5Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenk...
CVE-2020-2128MEDIUM4.3Jenkins ECX Copy Data Management Plugin 1.9 and earlier stores a password unencrypted in job config.xml files on the Jen...
CVE-2020-2127MEDIUM4.3Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configura...
CVE-2020-2126MEDIUM4.3Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins mast...
CVE-2020-2125MEDIUM4.3Jenkins Debian Package Builder Plugin 1.6.11 and earlier stores a GPG passphrase unencrypted in its global configuration...
CVE-2020-2124MEDIUM4.3Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files...
CVE-2020-2123HIGH8.8Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary typ...
CVE-2020-2122MEDIUM5.4Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resu...
CVE-2020-2121HIGH8.8Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiatio...
CVE-2020-2120HIGH8.8Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2119MEDIUM5.3Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins c...
CVE-2020-2118MEDIUM4.3A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allow...
CVE-2020-2117MEDIUM4.3A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now