CVEs from 2020

3,974 normalized CVEs published or assigned in this year.

Total
3,974
critical
critical 184
high
high 576
medium
medium 738
low
low 59
% Critical
4.6%
% with KEV
3.7%
% with exploit
5.1%

Top products

  • retail_xstore_point_of_service 33
  • banking_digital_experience 30
  • primavera_unifier 29
  • retail_service_backbone 15
  • financial_services_institutional_performance_analytics 13
  • insurance_policy_administration_j2ee 11
  • communications_network_charging_and_control 10
  • enterprise_manager_base_platform 10
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-12692 unknown 4y ago An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then …
CVE-2020-12689 unknown 4y ago An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escala…
CVE-2020-2187 unknown 4y ago Lack of SSL/TLS certificate and hostname validation in Amazon EC2 Plugin
CVE-2020-2182 unknown 4y ago Improper masking of some secrets in Jenkins Credentials Binding Plugin
CVE-2020-2183 unknown 4y ago Improper permission checks in Jenkins Copy Artifact Plugin
CVE-2020-2185 unknown 4y ago Missing SSH host key validation in Jenkins Amazon EC2 Plugin
CVE-2020-2181 unknown 4y ago Secrets are not masked by Jenkins Credentials Binding Plugin in builds without build steps
CVE-2020-2188 unknown 4y ago Users with Overall/Read access can enumerate credentials IDs in Amazon EC2 Plugin
CVE-2020-2186 unknown 4y ago CSRF vulnerability in Amazon EC2 Plugin
CVE-2020-2189 unknown 4y ago RCE vulnerability in SCM Filter Jervis Plugin
CVE-2020-2184 unknown 4y ago CSRF vulnerability in Jenkins CVS Plugin
CVE-2020-10686 unknown 4y ago Keycloak users may be able to remove MFA from other users' devices
CVE-2020-1745 unknown 4y ago Improper Authorization in Undertoe
CVE-2020-1757 unknown 4y ago Improper Input Validation in Undertow
CVE-2020-2178 unknown 4y ago XXE vulnerability in Jenkins Parasoft Findings Plugin
CVE-2020-2177 unknown 4y ago Credentials stored in plain text by Jenkins Copr Plugin
CVE-2020-2180 unknown 4y ago RCE vulnerability in Jenkins AWS SAM Plugin
CVE-2020-2179 unknown 4y ago RCE vulnerability in Jenkins Yaml Axis Plugin
CVE-2020-2173 unknown 4y ago XSS vulnerability in Jenkins Gatling Plugin
CVE-2020-2172 unknown 4y ago XXE vulnerability in Jenkins Code Coverage API Plugin
CVE-2020-2176 unknown 4y ago XSS vulnerability in Jenkins useMango Runner Plugin
CVE-2020-2174 unknown 4y ago Reflected XSS vulnerability in Jenkins AWSEB Deployment Plugin
CVE-2020-2175 unknown 4y ago Stored XSS vulnerability in Jenkins FitNesse Plugin
CVE-2020-7009 unknown 4y ago Improper Privilege Management in Elasticsearch
CVE-2020-7599 unknown 4y ago Exposure of Sensitive Information in Gradle publish plugin
CVE-2020-2171 unknown 4y ago XXE vulnerability in Jenkins RapidDeploy Plugin
CVE-2020-2168 unknown 4y ago RCE vulnerability in Jenkins Azure Container Service Plugin
CVE-2020-2169 unknown 4y ago Reflected XSS vulnerability in Jenkins Queue cleanup Plugin
CVE-2020-2165 unknown 4y ago Passwords transmitted in plain text by Jenkins Artifactory Plugin
CVE-2020-2162 unknown 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins
CVE-2020-2164 unknown 4y ago Passwords stored in plain text by Jenkins Artifactory Plugin
CVE-2020-2170 unknown 4y ago Stored XSS vulnerability in Jenkins RapidDeploy Plugin
CVE-2020-2161 unknown 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins
CVE-2020-2166 unknown 4y ago RCE vulnerability in Jenkins Pipeline: AWS Steps Plugin
CVE-2020-2160 unknown 4y ago Cross-Site Request Forgery in Jenkins
CVE-2020-2163 unknown 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins
CVE-2020-2159 unknown 4y ago OS command injection in CryptoMove Plugin
CVE-2020-2158 unknown 4y ago Remote Code Execution vulnerability in Jenkins Literate Plugin
CVE-2020-2157 unknown 4y ago Credentials transmitted in plain text by Skytap Cloud CI Plugin
CVE-2020-2156 unknown 4y ago Credentials transmitted in plain text by Jenkins DeployHub Plugin
CVE-2020-2152 unknown 4y ago Jenkins Subversion Release Manager Plugin vulnerable to cross-site scripting (XSS)
CVE-2020-2146 unknown 4y ago Missing SSH host key validation in Mac Plugin
CVE-2020-2148 unknown 4y ago Missing permission checks in Mac Plugin
CVE-2020-2153 unknown 4y ago Credentials transmitted in plain text by Backlog Plugin
CVE-2020-2154 unknown 4y ago Jenkins Zephyr for JIRA Test Management Plugin stores credentials in plain text
CVE-2020-2155 unknown 4y ago Credentials transmitted in plain text by OpenShift Deployer Plugin
CVE-2020-2150 unknown 4y ago Jenkins Sonar Quality Gates Plugin transmits credentials in plain text during configuration
CVE-2020-2143 unknown 4y ago Credentials transmitted in plain text by Jenkins Logstash Plugin
CVE-2020-2147 unknown 4y ago CSRF vulnerability in Mac Plugin
CVE-2020-2144 unknown 4y ago XXE vulnerability in Rundeck Plugin
CVE-2020-2151 unknown 4y ago Jenkins Quality Gates Plugin transmits credentials in plain text during configuration
CVE-2020-2138 unknown 4y ago XXE vulnerability in Jenkins Cobertura Plugin
CVE-2020-2145 unknown 4y ago Credentials stored in plain text by Zephyr Enterprise Test Management Plugin
CVE-2020-2149 unknown 4y ago Credentials transmitted in plain text by Repository Connector Plugin
CVE-2020-2142 unknown 4y ago Missing permission checks in Jenkins P4 Plugin
CVE-2020-2141 unknown 4y ago CSRF vulnerability in Jenkins P4 Plugin
CVE-2020-2135 unknown 4y ago Sandbox bypass vulnerability in Script Security Plugin
CVE-2020-2136 unknown 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins Git Plugin
CVE-2020-2140 unknown 4y ago XSS vulnerability in Jenkins Audit Trail Plugin
CVE-2020-2137 unknown 4y ago Stored XSS vulnerability in Jenkins Timestamper Plugin
CVE-2020-2139 unknown 4y ago Arbitrary file write vulnerability in Jenkins Cobertura Plugin
CVE-2020-2134 unknown 4y ago Sandbox bypass vulnerability in Script Security Plugin
CVE-2020-8441 unknown 4y ago Deserialization of Untrusted Data in JYaml
CVE-2020-2133 unknown 4y ago Password stored in plain text by Applatix Plugin
CVE-2020-2131 unknown 4y ago Passwords stored in plain text by Harvest SCM Plugin
CVE-2020-2130 unknown 4y ago Passwords stored in plain text by Harvest SCM Plugin
CVE-2020-2125 unknown 4y ago Credentials stored in plain text by debian-package-builder Plugin
CVE-2020-2129 unknown 4y ago Plaintext Storage of a Password in Jenkins Eagle Tester Plugin
CVE-2020-2128 unknown 4y ago Password stored in plain text by ECX Copy Data Management Plugin
CVE-2020-2122 unknown 4y ago Stored XSS vulnerability in Jenkins brakeman Plugin
CVE-2020-2121 unknown 4y ago RCE vulnerability in Google Kubernetes Engine Plugin
CVE-2020-2127 unknown 4y ago Credential stored in plain text by BMC Release Package and Deployment Plugin
CVE-2020-2132 unknown 4y ago Password stored in plain text by Parasoft Environment Manager Plugin
CVE-2020-2126 unknown 4y ago Token stored in plain text by DigitalOcean Plugin
CVE-2020-2123 unknown 4y ago RCE vulnerability in RadarGun Plugin
CVE-2020-2124 unknown 4y ago Password stored in plain text by Dynamic Extended Choice Parameter Plugin
CVE-2020-2120 unknown 4y ago XXE vulnerability in FitNesse Plugin
CVE-2020-2112 unknown 4y ago Jenkins Git Parameter Plugin vulnerable to Stored cross-site scripting (XSS)
CVE-2020-2116 unknown 4y ago CSRF vulnerability in Pipeline GitHub Notify Step Plugin allows capturing credentials
CVE-2020-2119 unknown 4y ago Client secret transmitted in plain text by Azure AD Plugin
CVE-2020-2113 unknown 4y ago Jenkins Git Parameter Plugin vulnerable to stored cross-site scripting (XSS)
CVE-2020-2109 unknown 4y ago Improper Input Validation in Jenkins Pipeline: Groovy Plugin
CVE-2020-2111 unknown 4y ago Subversion Plugin stored XSS vulnerability
CVE-2020-2118 unknown 4y ago Users with Overall/Read access can enumerate credential IDs in Pipeline GitHub Notify Step Plugin
CVE-2020-2114 unknown 4y ago Jenkins S3 Publisher Plugin transmits credentials in plain text during configuration
CVE-2020-2117 unknown 4y ago Missing permission checks in Pipeline GitHub Notify Step Plugin allows capturing credentials
CVE-2020-2115 unknown 4y ago XXE vulnerability in NUnit Plugin
CVE-2020-2110 unknown 4y ago Improper Input Validation in Jenkins Script Security Plugin
CVE-2020-2107 unknown 4y ago Fortify Plugin stored credentials in plain text
CVE-2020-2108 unknown 4y ago XXE vulnerability in Jenkins WebSphere Deployer Plugin
CVE-2020-2106 unknown 4y ago Stored XSS vulnerability in Code Coverage API Plugin
CVE-2020-2105 unknown 4y ago Jenkins REST APIs vulnerable to clickjacking
CVE-2020-2102 unknown 4y ago Non-constant time HMAC comparison
CVE-2020-2101 unknown 4y ago Non-constant time comparison of inbound TCP agent connection secret
CVE-2020-2099 unknown 4y ago Inbound TCP Agent Protocol/3 authentication bypass in Jenkins
CVE-2020-2103 unknown 4y ago Jenkins Diagnostic page exposed session cookies
CVE-2020-2100 unknown 4y ago Jenkins vulnerable to UDP amplification reflection attack
CVE-2020-2104 unknown 4y ago Memory usage graphs accessible to anyone with Overall/Read
CVE-2020-2097 unknown 4y ago Missing permission checks in Jenkins Sounds Plugin allow OS command execution
CVE-2020-2098 unknown 4y ago CSRF vulnerability in Jenkins Sounds Plugin allow OS command execution