2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2519 | MEDIUM | 4.3 | 1.2% | Jan 15, 2020 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions... |
| CVE-2020-2518 | HIGH | 7.5 | 1.3% | Jan 15, 2020 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.... |
| CVE-2020-2517 | LOW | 3.3 | 0.8% | Jan 15, 2020 | Vulnerability in the Database Gateway for ODBC component of Oracle Database Server. Supported versions that are affected... |
| CVE-2020-2516 | LOW | 2.4 | 0.8% | Jan 15, 2020 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, ... |
| CVE-2020-2515 | MEDIUM | 5 | 0.8% | Jan 15, 2020 | Vulnerability in the Database Gateway for ODBC component of Oracle Database Server. Supported versions that are affected... |
| CVE-2020-2512 | MEDIUM | 5.9 | 1.5% | Jan 15, 2020 | Vulnerability in the Database Gateway for ODBC component of Oracle Database Server. Supported versions that are affected... |
| CVE-2020-2511 | HIGH | 7.7 | 1.3% | Jan 15, 2020 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, ... |
| CVE-2020-2510 | HIGH | 7.5 | 2.1% | Jan 15, 2020 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, ... |
| CVE-2020-2098 | HIGH | 8.8 | 1.0% | Jan 15, 2020 | A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary... |
| CVE-2020-2097 | HIGH | 8.8 | 1.2% | Jan 15, 2020 | Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing at... |
| CVE-2020-2096 | MEDIUM | 6.1 | 89.4% | Jan 15, 2020 | Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a ref... |
| CVE-2020-2095 | MEDIUM | 4.3 | 0.9% | Jan 15, 2020 | Jenkins Redgate SQL Change Automation Plugin 2.0.4 and earlier stored an API key unencrypted in job config.xml files on ... |
| CVE-2020-2094 | MEDIUM | 4.3 | 0.8% | Jan 15, 2020 | A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/R... |
| CVE-2020-2093 | HIGH | 8.8 | 0.8% | Jan 15, 2020 | A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attacker... |
| CVE-2020-2092 | HIGH | 8.8 | 1.4% | Jan 15, 2020 | Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) ... |
| CVE-2020-2091 | HIGH | 8.1 | 1.1% | Jan 15, 2020 | A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission t... |
| CVE-2020-2090 | HIGH | 8.8 | 0.8% | Jan 15, 2020 | A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to ... |
| CVE-2020-1611 | MEDIUM | 6.5 | 1.7% | Jan 15, 2020 | A Local File Inclusion vulnerability in Juniper Networks Junos Space allows an attacker to view all files on the target ... |
| CVE-2020-1609 | HIGH | 8.8 | 0.9% | Jan 15, 2020 | When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos O... |
| CVE-2020-1608 | HIGH | 7.5 | 1.3% | Jan 15, 2020 | Receipt of a specific MPLS or IPv6 packet on the core facing interface of an MX Series device configured for Broadband E... |
| CVE-2020-1607 | MEDIUM | 6.1 | 0.9% | Jan 15, 2020 | Insufficient Cross-Site Scripting (XSS) protection in J-Web may potentially allow a remote attacker to inject web script... |
| CVE-2020-1606 | HIGH | 8.1 | 0.9% | Jan 15, 2020 | A path traversal vulnerability in the Juniper Networks Junos OS device may allow an authenticated J-web user to read fil... |
| CVE-2020-1605 | HIGH | 8.8 | 0.8% | Jan 15, 2020 | When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos O... |
| CVE-2020-1604 | MEDIUM | 5.3 | 0.8% | Jan 15, 2020 | On EX4300, EX4600, QFX3500, and QFX5100 Series, a vulnerability in the IP firewall filter component may cause the firewa... |
| CVE-2020-1603 | HIGH | 8.6 | 1.4% | Jan 15, 2020 | Specific IPv6 packets sent by clients processed by the Routing Engine (RE) are improperly handled. These IPv6 packets ar... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now