2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8443CRITICAL9.8In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an...
CVE-2020-8442HIGH8.8In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a ...
CVE-2020-8438HIGH7.2Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hid...
CVE-2020-8432CRITICAL9.8In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double free...
CVE-2020-3758MEDIUM6.1Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cros...
CVE-2020-3719HIGH7.5Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql inject...
CVE-2020-3718CRITICAL9.8Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security by...
CVE-2020-3717MEDIUM5.3Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traver...
CVE-2020-3716CRITICAL9.8Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserializa...
CVE-2020-3715MEDIUM6.1Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cros...
CVE-2020-3714HIGH7.8Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea...
CVE-2020-3713HIGH7.8Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea...
CVE-2020-3712HIGH7.8Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea...
CVE-2020-3711HIGH7.8Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea...
CVE-2020-3710HIGH7.8Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea...
CVE-2020-8416HIGH7.5IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to th...
CVE-2020-7247CRITICAL9.8smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to ...
CVE-2020-2108HIGH7.6Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can b...
CVE-2020-2107MEDIUM4.3Jenkins Fortify Plugin 19.1.29 and earlier stores proxy server passwords unencrypted in job config.xml files on the Jenk...
CVE-2020-2106MEDIUM5.4Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view,...
CVE-2020-2105MEDIUM5.4REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
CVE-2020-2104MEDIUM4.3Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage cha...
CVE-2020-2103MEDIUM5.4Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI d...
CVE-2020-2102MEDIUM5.3Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
CVE-2020-2101MEDIUM5.3Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connec...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now