2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-2519MEDIUM4.3Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions...
CVE-2020-2518HIGH7.5Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12....
CVE-2020-2517LOW3.3Vulnerability in the Database Gateway for ODBC component of Oracle Database Server. Supported versions that are affected...
CVE-2020-2516LOW2.4Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, ...
CVE-2020-2515MEDIUM5Vulnerability in the Database Gateway for ODBC component of Oracle Database Server. Supported versions that are affected...
CVE-2020-2512MEDIUM5.9Vulnerability in the Database Gateway for ODBC component of Oracle Database Server. Supported versions that are affected...
CVE-2020-2511HIGH7.7Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, ...
CVE-2020-2510HIGH7.5Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, ...
CVE-2020-2098HIGH8.8A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary...
CVE-2020-2097HIGH8.8Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing at...
CVE-2020-2096MEDIUM6.1Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a ref...
CVE-2020-2095MEDIUM4.3Jenkins Redgate SQL Change Automation Plugin 2.0.4 and earlier stored an API key unencrypted in job config.xml files on ...
CVE-2020-2094MEDIUM4.3A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/R...
CVE-2020-2093HIGH8.8A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attacker...
CVE-2020-2092HIGH8.8Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) ...
CVE-2020-2091HIGH8.1A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission t...
CVE-2020-2090HIGH8.8A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to ...
CVE-2020-1611MEDIUM6.5A Local File Inclusion vulnerability in Juniper Networks Junos Space allows an attacker to view all files on the target ...
CVE-2020-1609HIGH8.8When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos O...
CVE-2020-1608HIGH7.5Receipt of a specific MPLS or IPv6 packet on the core facing interface of an MX Series device configured for Broadband E...
CVE-2020-1607MEDIUM6.1Insufficient Cross-Site Scripting (XSS) protection in J-Web may potentially allow a remote attacker to inject web script...
CVE-2020-1606HIGH8.1A path traversal vulnerability in the Juniper Networks Junos OS device may allow an authenticated J-web user to read fil...
CVE-2020-1605HIGH8.8When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos O...
CVE-2020-1604MEDIUM5.3On EX4300, EX4600, QFX3500, and QFX5100 Series, a vulnerability in the IP firewall filter component may cause the firewa...
CVE-2020-1603HIGH8.6Specific IPv6 packets sent by clients processed by the Routing Engine (RE) are improperly handled. These IPv6 packets ar...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now