CVEs from 2020

3,992 normalized CVEs published or assigned in this year.

Total
3,992
critical
critical 169
high
high 590
medium
medium 739
low
low 59
% Critical
4.2%
% with KEV
3.7%
% with exploit
4.0%

Top products

  • retail_xstore_point_of_service 33
  • banking_digital_experience 30
  • primavera_unifier 29
  • retail_service_backbone 15
  • financial_services_institutional_performance_analytics 13
  • insurance_policy_administration_j2ee 11
  • communications_network_charging_and_control 10
  • enterprise_manager_base_platform 10
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-2178 unknown 4y ago XXE vulnerability in Jenkins Parasoft Findings Plugin
CVE-2020-2180 unknown 4y ago RCE vulnerability in Jenkins AWS SAM Plugin
CVE-2020-2177 unknown 4y ago Credentials stored in plain text by Jenkins Copr Plugin
CVE-2020-2179 unknown 4y ago RCE vulnerability in Jenkins Yaml Axis Plugin
CVE-2020-2174 unknown 4y ago Reflected XSS vulnerability in Jenkins AWSEB Deployment Plugin
CVE-2020-2176 unknown 4y ago XSS vulnerability in Jenkins useMango Runner Plugin
CVE-2020-2175 unknown 4y ago Stored XSS vulnerability in Jenkins FitNesse Plugin
CVE-2020-2172 unknown 4y ago XXE vulnerability in Jenkins Code Coverage API Plugin
CVE-2020-2173 unknown 4y ago XSS vulnerability in Jenkins Gatling Plugin
CVE-2020-7009 unknown 4y ago Improper Privilege Management in Elasticsearch
CVE-2020-7599 unknown 4y ago Exposure of Sensitive Information in Gradle publish plugin
CVE-2020-2169 unknown 4y ago Reflected XSS vulnerability in Jenkins Queue cleanup Plugin
CVE-2020-2171 unknown 4y ago XXE vulnerability in Jenkins RapidDeploy Plugin
CVE-2020-2168 unknown 4y ago RCE vulnerability in Jenkins Azure Container Service Plugin
CVE-2020-2163 unknown 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins
CVE-2020-2160 unknown 4y ago Cross-Site Request Forgery in Jenkins
CVE-2020-2170 unknown 4y ago Stored XSS vulnerability in Jenkins RapidDeploy Plugin
CVE-2020-2166 unknown 4y ago RCE vulnerability in Jenkins Pipeline: AWS Steps Plugin
CVE-2020-2164 unknown 4y ago Passwords stored in plain text by Jenkins Artifactory Plugin
CVE-2020-2165 unknown 4y ago Passwords transmitted in plain text by Jenkins Artifactory Plugin
CVE-2020-2161 unknown 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins
CVE-2020-2162 unknown 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins
CVE-2020-2157 unknown 4y ago Credentials transmitted in plain text by Skytap Cloud CI Plugin
CVE-2020-2158 unknown 4y ago Remote Code Execution vulnerability in Jenkins Literate Plugin
CVE-2020-2159 unknown 4y ago OS command injection in CryptoMove Plugin
CVE-2020-2154 unknown 4y ago Jenkins Zephyr for JIRA Test Management Plugin stores credentials in plain text
CVE-2020-2146 unknown 4y ago Missing SSH host key validation in Mac Plugin
CVE-2020-2156 unknown 4y ago Credentials transmitted in plain text by Jenkins DeployHub Plugin
CVE-2020-2148 unknown 4y ago Missing permission checks in Mac Plugin
CVE-2020-2153 unknown 4y ago Credentials transmitted in plain text by Backlog Plugin
CVE-2020-2152 unknown 4y ago Jenkins Subversion Release Manager Plugin vulnerable to cross-site scripting (XSS)
CVE-2020-2155 unknown 4y ago Credentials transmitted in plain text by OpenShift Deployer Plugin
CVE-2020-2141 unknown 4y ago CSRF vulnerability in Jenkins P4 Plugin
CVE-2020-2144 unknown 4y ago XXE vulnerability in Rundeck Plugin
CVE-2020-2143 unknown 4y ago Credentials transmitted in plain text by Jenkins Logstash Plugin
CVE-2020-2150 unknown 4y ago Jenkins Sonar Quality Gates Plugin transmits credentials in plain text during configuration
CVE-2020-2145 unknown 4y ago Credentials stored in plain text by Zephyr Enterprise Test Management Plugin
CVE-2020-2149 unknown 4y ago Credentials transmitted in plain text by Repository Connector Plugin
CVE-2020-2151 unknown 4y ago Jenkins Quality Gates Plugin transmits credentials in plain text during configuration
CVE-2020-2142 unknown 4y ago Missing permission checks in Jenkins P4 Plugin
CVE-2020-2138 unknown 4y ago XXE vulnerability in Jenkins Cobertura Plugin
CVE-2020-2147 unknown 4y ago CSRF vulnerability in Mac Plugin
CVE-2020-2139 unknown 4y ago Arbitrary file write vulnerability in Jenkins Cobertura Plugin
CVE-2020-2140 unknown 4y ago XSS vulnerability in Jenkins Audit Trail Plugin
CVE-2020-2135 unknown 4y ago Sandbox bypass vulnerability in Script Security Plugin
CVE-2020-2134 unknown 4y ago Sandbox bypass vulnerability in Script Security Plugin
CVE-2020-2136 unknown 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins Git Plugin
CVE-2020-2137 unknown 4y ago Stored XSS vulnerability in Jenkins Timestamper Plugin
CVE-2020-8441 unknown 4y ago Deserialization of Untrusted Data in JYaml
CVE-2020-2131 unknown 4y ago Passwords stored in plain text by Harvest SCM Plugin
CVE-2020-2133 unknown 4y ago Password stored in plain text by Applatix Plugin
CVE-2020-2130 unknown 4y ago Passwords stored in plain text by Harvest SCM Plugin
CVE-2020-2128 unknown 4y ago Password stored in plain text by ECX Copy Data Management Plugin
CVE-2020-2132 unknown 4y ago Password stored in plain text by Parasoft Environment Manager Plugin
CVE-2020-2123 unknown 4y ago RCE vulnerability in RadarGun Plugin
CVE-2020-2124 unknown 4y ago Password stored in plain text by Dynamic Extended Choice Parameter Plugin
CVE-2020-2120 unknown 4y ago XXE vulnerability in FitNesse Plugin
CVE-2020-2121 unknown 4y ago RCE vulnerability in Google Kubernetes Engine Plugin
CVE-2020-2127 unknown 4y ago Credential stored in plain text by BMC Release Package and Deployment Plugin
CVE-2020-2125 unknown 4y ago Credentials stored in plain text by debian-package-builder Plugin
CVE-2020-2122 unknown 4y ago Stored XSS vulnerability in Jenkins brakeman Plugin
CVE-2020-2126 unknown 4y ago Token stored in plain text by DigitalOcean Plugin
CVE-2020-2129 unknown 4y ago Plaintext Storage of a Password in Jenkins Eagle Tester Plugin
CVE-2020-2117 unknown 4y ago Missing permission checks in Pipeline GitHub Notify Step Plugin allows capturing credentials
CVE-2020-2118 unknown 4y ago Users with Overall/Read access can enumerate credential IDs in Pipeline GitHub Notify Step Plugin
CVE-2020-2109 unknown 4y ago Improper Input Validation in Jenkins Pipeline: Groovy Plugin
CVE-2020-2115 unknown 4y ago XXE vulnerability in NUnit Plugin
CVE-2020-2111 unknown 4y ago Subversion Plugin stored XSS vulnerability
CVE-2020-2112 unknown 4y ago Jenkins Git Parameter Plugin vulnerable to Stored cross-site scripting (XSS)
CVE-2020-2119 unknown 4y ago Client secret transmitted in plain text by Azure AD Plugin
CVE-2020-2114 unknown 4y ago Jenkins S3 Publisher Plugin transmits credentials in plain text during configuration
CVE-2020-2116 unknown 4y ago CSRF vulnerability in Pipeline GitHub Notify Step Plugin allows capturing credentials
CVE-2020-2113 unknown 4y ago Jenkins Git Parameter Plugin vulnerable to stored cross-site scripting (XSS)
CVE-2020-2110 unknown 4y ago Improper Input Validation in Jenkins Script Security Plugin
CVE-2020-2106 unknown 4y ago Stored XSS vulnerability in Code Coverage API Plugin
CVE-2020-2107 unknown 4y ago Fortify Plugin stored credentials in plain text
CVE-2020-2105 unknown 4y ago Jenkins REST APIs vulnerable to clickjacking
CVE-2020-2108 unknown 4y ago XXE vulnerability in Jenkins WebSphere Deployer Plugin
CVE-2020-2101 unknown 4y ago Non-constant time comparison of inbound TCP agent connection secret
CVE-2020-2104 unknown 4y ago Memory usage graphs accessible to anyone with Overall/Read
CVE-2020-2102 unknown 4y ago Non-constant time HMAC comparison
CVE-2020-2099 unknown 4y ago Inbound TCP Agent Protocol/3 authentication bypass in Jenkins
CVE-2020-2100 unknown 4y ago Jenkins vulnerable to UDP amplification reflection attack
CVE-2020-2103 unknown 4y ago Jenkins Diagnostic page exposed session cookies
CVE-2020-7934 unknown 4y ago Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet
CVE-2020-2095 unknown 4y ago Redgate SQL Change Automation Plugin stored credentials in plain text
CVE-2020-2098 unknown 4y ago CSRF vulnerability in Jenkins Sounds Plugin allow OS command execution
CVE-2020-2094 unknown 4y ago Missing permission checks in Health Advisor by CloudBees Plugin
CVE-2020-2097 unknown 4y ago Missing permission checks in Jenkins Sounds Plugin allow OS command execution
CVE-2020-2092 unknown 4y ago XXE vulnerability in Jenkins Robot Framework Plugin
CVE-2020-2096 unknown 4y ago Reflected XSS vulnerability in Jenkins gitlab-hook Plugin
CVE-2020-2091 unknown 4y ago Missing permission checks in Jenkins Amazon EC2 Plugin
CVE-2020-2093 unknown 4y ago CSRF vulnerability in Health Advisor by CloudBees Plugin
CVE-2020-2090 unknown 4y ago CSRF vulnerability in Jenkins Amazon EC2 Plugin
CVE-2020-14326 unknown 4y ago RESTEasy 4.5.5.Final in hash flooding
CVE-2020-35510 unknown 4y ago Uncontrolled Resource Consumption in jboss-remoting
CVE-2020-1729 unknown 4y ago Permissions bypass in SmallRye
CVE-2020-28466 unknown 4y ago This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer fro…
CVE-2020-10714 unknown 4y ago Session Fixation in WildFly Elytron
CVE-2020-1748 unknown 4y ago Incorrect Authorization in WildFly Elytron