2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2116 | HIGH | 8.8 | 0.7% | Feb 12, 2020 | A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attack... |
| CVE-2020-2115 | HIGH | 8.8 | 1.1% | Feb 12, 2020 | Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2020-2114 | HIGH | 7.5 | 1.1% | Feb 12, 2020 | Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenk... |
| CVE-2020-2113 | MEDIUM | 5.4 | 0.7% | Feb 12, 2020 | Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored... |
| CVE-2020-2112 | MEDIUM | 5.4 | 0.7% | Feb 12, 2020 | Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a store... |
| CVE-2020-2111 | MEDIUM | 5.4 | 0.9% | Feb 12, 2020 | Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field... |
| CVE-2020-2110 | HIGH | 8.8 | 1.3% | Feb 12, 2020 | Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilatio... |
| CVE-2020-2109 | HIGH | 8.8 | 1.3% | Feb 12, 2020 | Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter exp... |
| CVE-2020-8894 | MEDIUM | 6.5 | 1.4% | Feb 12, 2020 | An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsCon... |
| CVE-2020-8893 | HIGH | 7.5 | 2.0% | Feb 12, 2020 | An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/... |
| CVE-2020-8892 | HIGH | 8.1 | 1.7% | Feb 12, 2020 | An issue was discovered in MISP before 2.4.121. It did not consider the HTTP PUT method when trying to block a brute-for... |
| CVE-2020-8891 | MEDIUM | 5.9 | 1.4% | Feb 12, 2020 | An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force ser... |
| CVE-2020-8890 | MEDIUM | 5.9 | 1.1% | Feb 12, 2020 | An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and ... |
| CVE-2020-0792 | HIGH | 8.8 | 1.3% | Feb 11, 2020 | An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory,... |
| CVE-2020-0767 | HIGH | 7.5 | 17.6% | Feb 11, 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, ... |
| CVE-2020-0759 | HIGH | 8.8 | 14.8% | Feb 11, 2020 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2020-0757 | HIGH | 7.8 | 0.9% | Feb 11, 2020 | An elevation of privilege vulnerability exists when Windows improperly handles Secure Socket Shell remote commands, aka ... |
| CVE-2020-0756 | MEDIUM | 5.5 | 1.6% | Feb 11, 2020 | An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper... |
| CVE-2020-0755 | MEDIUM | 5.5 | 1.6% | Feb 11, 2020 | An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper... |
| CVE-2020-0754 | HIGH | 7.8 | 1.5% | Feb 11, 2020 | An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka... |
| CVE-2020-0753 | HIGH | 7.8 | 2.3% | Feb 11, 2020 | An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka... |
| CVE-2020-0752 | HIGH | 7.8 | 0.8% | Feb 11, 2020 | An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka... |
| CVE-2020-0751 | MEDIUM | 6 | 1.4% | Feb 11, 2020 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific mal... |
| CVE-2020-0750 | HIGH | 7.8 | 0.8% | Feb 11, 2020 | An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in... |
| CVE-2020-0749 | HIGH | 7.8 | 0.8% | Feb 11, 2020 | An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now