2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-2116HIGH8.8A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attack...
CVE-2020-2115HIGH8.8Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2114HIGH7.5Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenk...
CVE-2020-2113MEDIUM5.4Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored...
CVE-2020-2112MEDIUM5.4Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a store...
CVE-2020-2111MEDIUM5.4Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field...
CVE-2020-2110HIGH8.8Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilatio...
CVE-2020-2109HIGH8.8Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter exp...
CVE-2020-8894MEDIUM6.5An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsCon...
CVE-2020-8893HIGH7.5An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/...
CVE-2020-8892HIGH8.1An issue was discovered in MISP before 2.4.121. It did not consider the HTTP PUT method when trying to block a brute-for...
CVE-2020-8891MEDIUM5.9An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force ser...
CVE-2020-8890MEDIUM5.9An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and ...
CVE-2020-0792HIGH8.8An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory,...
CVE-2020-0767HIGH7.5A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, ...
CVE-2020-0759HIGH8.8A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje...
CVE-2020-0757HIGH7.8An elevation of privilege vulnerability exists when Windows improperly handles Secure Socket Shell remote commands, aka ...
CVE-2020-0756MEDIUM5.5An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper...
CVE-2020-0755MEDIUM5.5An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper...
CVE-2020-0754HIGH7.8An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka...
CVE-2020-0753HIGH7.8An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka...
CVE-2020-0752HIGH7.8An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka...
CVE-2020-0751MEDIUM6A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific mal...
CVE-2020-0750HIGH7.8An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in...
CVE-2020-0749HIGH7.8An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now