CVEs from 2020
Total
3,897
critical
critical 184
high
high 576
medium
medium 738
low
low 59
% Critical
4.7%
% with KEV
3.7%
% with exploit
5.2%
Top vendors
Top products
- retail_xstore_point_of_service 33
- banking_digital_experience 30
- primavera_unifier 29
- retail_service_backbone 15
- financial_services_institutional_performance_analytics 13
- insurance_policy_administration_j2ee 11
- communications_network_charging_and_control 10
- enterprise_manager_base_platform 10
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-7009 | unknown | — | — | 4y ago | Improper Privilege Management in Elasticsearch | |||
| CVE-2020-7599 | unknown | — | — | 4y ago | Exposure of Sensitive Information in Gradle publish plugin | |||
| CVE-2020-2168 | unknown | — | — | 4y ago | RCE vulnerability in Jenkins Azure Container Service Plugin | |||
| CVE-2020-2171 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins RapidDeploy Plugin | |||
| CVE-2020-2169 | unknown | — | — | 4y ago | Reflected XSS vulnerability in Jenkins Queue cleanup Plugin | |||
| CVE-2020-2166 | unknown | — | — | 4y ago | RCE vulnerability in Jenkins Pipeline: AWS Steps Plugin | |||
| CVE-2020-2164 | unknown | — | — | 4y ago | Passwords stored in plain text by Jenkins Artifactory Plugin | |||
| CVE-2020-2160 | unknown | — | — | 4y ago | Cross-Site Request Forgery in Jenkins | |||
| CVE-2020-2165 | unknown | — | — | 4y ago | Passwords transmitted in plain text by Jenkins Artifactory Plugin | |||
| CVE-2020-2170 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins RapidDeploy Plugin | |||
| CVE-2020-2162 | unknown | — | — | 4y ago | Improper Neutralization of Input During Web Page Generation in Jenkins | |||
| CVE-2020-2163 | unknown | — | — | 4y ago | Improper Neutralization of Input During Web Page Generation in Jenkins | |||
| CVE-2020-2161 | unknown | — | — | 4y ago | Improper Neutralization of Input During Web Page Generation in Jenkins | |||
| CVE-2020-2158 | unknown | — | — | 4y ago | Remote Code Execution vulnerability in Jenkins Literate Plugin | |||
| CVE-2020-2157 | unknown | — | — | 4y ago | Credentials transmitted in plain text by Skytap Cloud CI Plugin | |||
| CVE-2020-2159 | unknown | — | — | 4y ago | OS command injection in CryptoMove Plugin | |||
| CVE-2020-2148 | unknown | — | — | 4y ago | Missing permission checks in Mac Plugin | |||
| CVE-2020-2153 | unknown | — | — | 4y ago | Credentials transmitted in plain text by Backlog Plugin | |||
| CVE-2020-2146 | unknown | — | — | 4y ago | Missing SSH host key validation in Mac Plugin | |||
| CVE-2020-2156 | unknown | — | — | 4y ago | Credentials transmitted in plain text by Jenkins DeployHub Plugin | |||
| CVE-2020-2154 | unknown | — | — | 4y ago | Jenkins Zephyr for JIRA Test Management Plugin stores credentials in plain text | |||
| CVE-2020-2155 | unknown | — | — | 4y ago | Credentials transmitted in plain text by OpenShift Deployer Plugin | |||
| CVE-2020-2152 | unknown | — | — | 4y ago | Jenkins Subversion Release Manager Plugin vulnerable to cross-site scripting (XSS) | |||
| CVE-2020-2141 | unknown | — | — | 4y ago | CSRF vulnerability in Jenkins P4 Plugin | |||
| CVE-2020-2145 | unknown | — | — | 4y ago | Credentials stored in plain text by Zephyr Enterprise Test Management Plugin | |||
| CVE-2020-2142 | unknown | — | — | 4y ago | Missing permission checks in Jenkins P4 Plugin | |||
| CVE-2020-2138 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins Cobertura Plugin | |||
| CVE-2020-2147 | unknown | — | — | 4y ago | CSRF vulnerability in Mac Plugin | |||
| CVE-2020-2149 | unknown | — | — | 4y ago | Credentials transmitted in plain text by Repository Connector Plugin | |||
| CVE-2020-2151 | unknown | — | — | 4y ago | Jenkins Quality Gates Plugin transmits credentials in plain text during configuration | |||
| CVE-2020-2144 | unknown | — | — | 4y ago | XXE vulnerability in Rundeck Plugin | |||
| CVE-2020-2143 | unknown | — | — | 4y ago | Credentials transmitted in plain text by Jenkins Logstash Plugin | |||
| CVE-2020-2150 | unknown | — | — | 4y ago | Jenkins Sonar Quality Gates Plugin transmits credentials in plain text during configuration | |||
| CVE-2020-2134 | unknown | — | — | 4y ago | Sandbox bypass vulnerability in Script Security Plugin | |||
| CVE-2020-2137 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins Timestamper Plugin | |||
| CVE-2020-2136 | unknown | — | — | 4y ago | Improper Neutralization of Input During Web Page Generation in Jenkins Git Plugin | |||
| CVE-2020-2135 | unknown | — | — | 4y ago | Sandbox bypass vulnerability in Script Security Plugin | |||
| CVE-2020-2139 | unknown | — | — | 4y ago | Arbitrary file write vulnerability in Jenkins Cobertura Plugin | |||
| CVE-2020-2140 | unknown | — | — | 4y ago | XSS vulnerability in Jenkins Audit Trail Plugin | |||
| CVE-2020-8441 | unknown | — | — | 4y ago | Deserialization of Untrusted Data in JYaml | |||
| CVE-2020-2133 | unknown | — | — | 4y ago | Password stored in plain text by Applatix Plugin | |||
| CVE-2020-2131 | unknown | — | — | 4y ago | Passwords stored in plain text by Harvest SCM Plugin | |||
| CVE-2020-2130 | unknown | — | — | 4y ago | Passwords stored in plain text by Harvest SCM Plugin | |||
| CVE-2020-2124 | unknown | — | — | 4y ago | Password stored in plain text by Dynamic Extended Choice Parameter Plugin | |||
| CVE-2020-2121 | unknown | — | — | 4y ago | RCE vulnerability in Google Kubernetes Engine Plugin | |||
| CVE-2020-2127 | unknown | — | — | 4y ago | Credential stored in plain text by BMC Release Package and Deployment Plugin | |||
| CVE-2020-2126 | unknown | — | — | 4y ago | Token stored in plain text by DigitalOcean Plugin | |||
| CVE-2020-2122 | unknown | — | — | 4y ago | Stored XSS vulnerability in Jenkins brakeman Plugin | |||
| CVE-2020-2120 | unknown | — | — | 4y ago | XXE vulnerability in FitNesse Plugin | |||
| CVE-2020-2125 | unknown | — | — | 4y ago | Credentials stored in plain text by debian-package-builder Plugin | |||
| CVE-2020-2123 | unknown | — | — | 4y ago | RCE vulnerability in RadarGun Plugin | |||
| CVE-2020-2128 | unknown | — | — | 4y ago | Password stored in plain text by ECX Copy Data Management Plugin | |||
| CVE-2020-2132 | unknown | — | — | 4y ago | Password stored in plain text by Parasoft Environment Manager Plugin | |||
| CVE-2020-2129 | unknown | — | — | 4y ago | Plaintext Storage of a Password in Jenkins Eagle Tester Plugin | |||
| CVE-2020-2116 | unknown | — | — | 4y ago | CSRF vulnerability in Pipeline GitHub Notify Step Plugin allows capturing credentials | |||
| CVE-2020-2113 | unknown | — | — | 4y ago | Jenkins Git Parameter Plugin vulnerable to stored cross-site scripting (XSS) | |||
| CVE-2020-2115 | unknown | — | — | 4y ago | XXE vulnerability in NUnit Plugin | |||
| CVE-2020-2118 | unknown | — | — | 4y ago | Users with Overall/Read access can enumerate credential IDs in Pipeline GitHub Notify Step Plugin | |||
| CVE-2020-2119 | unknown | — | — | 4y ago | Client secret transmitted in plain text by Azure AD Plugin | |||
| CVE-2020-2112 | unknown | — | — | 4y ago | Jenkins Git Parameter Plugin vulnerable to Stored cross-site scripting (XSS) | |||
| CVE-2020-2114 | unknown | — | — | 4y ago | Jenkins S3 Publisher Plugin transmits credentials in plain text during configuration | |||
| CVE-2020-2109 | unknown | — | — | 4y ago | Improper Input Validation in Jenkins Pipeline: Groovy Plugin | |||
| CVE-2020-2111 | unknown | — | — | 4y ago | Subversion Plugin stored XSS vulnerability | |||
| CVE-2020-2117 | unknown | — | — | 4y ago | Missing permission checks in Pipeline GitHub Notify Step Plugin allows capturing credentials | |||
| CVE-2020-2110 | unknown | — | — | 4y ago | Improper Input Validation in Jenkins Script Security Plugin | |||
| CVE-2020-2108 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins WebSphere Deployer Plugin | |||
| CVE-2020-2107 | unknown | — | — | 4y ago | Fortify Plugin stored credentials in plain text | |||
| CVE-2020-2106 | unknown | — | — | 4y ago | Stored XSS vulnerability in Code Coverage API Plugin | |||
| CVE-2020-2105 | unknown | — | — | 4y ago | Jenkins REST APIs vulnerable to clickjacking | |||
| CVE-2020-2100 | unknown | — | — | 4y ago | Jenkins vulnerable to UDP amplification reflection attack | |||
| CVE-2020-2102 | unknown | — | — | 4y ago | Non-constant time HMAC comparison | |||
| CVE-2020-2104 | unknown | — | — | 4y ago | Memory usage graphs accessible to anyone with Overall/Read | |||
| CVE-2020-2099 | unknown | — | — | 4y ago | Inbound TCP Agent Protocol/3 authentication bypass in Jenkins | |||
| CVE-2020-2103 | unknown | — | — | 4y ago | Jenkins Diagnostic page exposed session cookies | |||
| CVE-2020-2101 | unknown | — | — | 4y ago | Non-constant time comparison of inbound TCP agent connection secret | |||
| CVE-2020-2095 | unknown | — | — | 4y ago | Redgate SQL Change Automation Plugin stored credentials in plain text | |||
| CVE-2020-2098 | unknown | — | — | 4y ago | CSRF vulnerability in Jenkins Sounds Plugin allow OS command execution | |||
| CVE-2020-2092 | unknown | — | — | 4y ago | XXE vulnerability in Jenkins Robot Framework Plugin | |||
| CVE-2020-2097 | unknown | — | — | 4y ago | Missing permission checks in Jenkins Sounds Plugin allow OS command execution | |||
| CVE-2020-2094 | unknown | — | — | 4y ago | Missing permission checks in Health Advisor by CloudBees Plugin | |||
| CVE-2020-2093 | unknown | — | — | 4y ago | CSRF vulnerability in Health Advisor by CloudBees Plugin | |||
| CVE-2020-2090 | unknown | — | — | 4y ago | CSRF vulnerability in Jenkins Amazon EC2 Plugin | |||
| CVE-2020-2091 | unknown | — | — | 4y ago | Missing permission checks in Jenkins Amazon EC2 Plugin | |||
| CVE-2020-14326 | unknown | — | — | 4y ago | RESTEasy 4.5.5.Final in hash flooding | |||
| CVE-2020-35510 | unknown | — | — | 4y ago | Uncontrolled Resource Consumption in jboss-remoting | |||
| CVE-2020-1729 | unknown | — | — | 4y ago | Permissions bypass in SmallRye | |||
| CVE-2020-28466 | unknown | — | — | 4y ago | This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer fro… | |||
| CVE-2020-13401 | unknown | — | — | 4y ago | An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts… | |||
| CVE-2020-10714 | unknown | — | — | 4y ago | Session Fixation in WildFly Elytron | |||
| CVE-2020-1748 | unknown | — | — | 4y ago | Incorrect Authorization in WildFly Elytron | |||
| CVE-2020-25640 | unknown | — | — | 4y ago | Wildfly logs plaintext passwords | |||
| CVE-2020-14338 | unknown | — | — | 4y ago | Improper Input Validation in Xerces | |||
| CVE-2020-15157 | unknown | — | — | 4y ago | In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Sche… | |||
| CVE-2020-11969 | unknown | — | — | 4y ago | Missing Authentication for Critical Function in Apache TomEE | |||
| CVE-2020-9296 | unknown | — | — | 4y ago | Expression Language Injection in Netflix Conductor | |||
| CVE-2020-9495 | unknown | — | — | 4y ago | Injection in Apache Archiva | |||
| CVE-2020-9480 | unknown | — | — | 4y ago | Improper Authentication in Apache Spark | |||
| CVE-2020-11980 | unknown | — | — | 4y ago | Server-Side Request Forgery in Karaf | |||
| CVE-2020-13973 | unknown | — | — | 4y ago | Cross-site scripting in json-sanitizer | |||
| CVE-2020-15813 | unknown | — | — | 4y ago | Improper Certificate Validation in Graylog |