CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-2158

    Last Modified: 21 Nov 2024

    Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

    Published: 9 Mar 2020
    8.8
    High

    CVE-2020-2159

    Last Modified: 21 Nov 2024

    Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the OS user account running Jenkins.

    Published: 9 Mar 2020
    5.3
    Medium

    CVE-2020-2155

    Last Modified: 21 Nov 2024

    Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

    Published: 9 Mar 2020
    4.3
    Medium

    CVE-2020-2156

    Last Modified: 21 Nov 2024

    Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.

    Published: 9 Mar 2020
    4.3
    Medium

    CVE-2020-2157

    Last Modified: 21 Nov 2024

    Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.

    Published: 9 Mar 2020
    5.5
    Medium

    CVE-2020-2154

    Last Modified: 21 Nov 2024

    Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configuration file on the Jenkins master file system.

    Published: 9 Mar 2020
    4.3
    Medium

    CVE-2020-2153

    Last Modified: 21 Nov 2024

    Jenkins Backlog Plugin 2.4 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.

    Published: 9 Mar 2020
    5.3
    Medium

    CVE-2020-2151

    Last Modified: 21 Nov 2024

    Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

    Published: 9 Mar 2020
    5.3
    Medium

    CVE-2020-2149

    Last Modified: 21 Nov 2024

    Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

    Published: 9 Mar 2020
    5.3
    Medium

    CVE-2020-2150

    Last Modified: 21 Nov 2024

    Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

    Published: 9 Mar 2020
    4.3
    Medium

    CVE-2020-2148

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.

    Published: 9 Mar 2020
    7.4
    High

    CVE-2020-2146

    Last Modified: 21 Nov 2024

    Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.

    Published: 9 Mar 2020
    4.3
    Medium

    CVE-2020-2147

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Mac Plugin 1.1.0 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.

    Published: 9 Mar 2020
    5.5
    Medium

    CVE-2020-2145

    Last Modified: 21 Nov 2024

    Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system.

    Published: 9 Mar 2020
    7.1
    High

    CVE-2020-2144

    Last Modified: 21 Nov 2024

    Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 9 Mar 2020
    4.3
    Medium

    CVE-2020-2142

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins P4 Plugin 1.10.10 and earlier allows attackers with Overall/Read permission to trigger builds.

    Published: 9 Mar 2020
    5.3
    Medium

    CVE-2020-2143

    Last Modified: 21 Nov 2024

    Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

    Published: 9 Mar 2020
    4.3
    Medium

    CVE-2020-2141

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins P4 Plugin 1.10.10 and earlier allows attackers to trigger builds or add a labels in Perforce.

    Published: 9 Mar 2020
    6.1
    Medium

    CVE-2020-2140

    Last Modified: 21 Nov 2024

    Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.

    Published: 9 Mar 2020
    4.8
    Medium

    CVE-2020-2137

    Last Modified: 21 Nov 2024

    Jenkins Timestamper Plugin 1.11.1 and earlier does not sanitize HTML formatting of its output, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.

    Published: 9 Mar 2020
    7.5
    High

    CVE-2020-4217

    Last Modified: 21 Nov 2024

    The IBM Spectrum Scale 4.2 and 5.0 file system component is affected by a denial of service security vulnerability. An attacker can force the Spectrum Scale mmfsd/mmsdrserv daemons to unexpectedly exit, impacting the functionality of the Spectrum Scale cluster and the availability of file systems managed by Spectrum Scale. IBM X-Force ID: 175067.

    Published: 9 Mar 2020
    —
    Unknown

    CVE-2020-10175

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 9 Mar 2020
    4.3
    Medium

    CVE-2020-9386

    Last Modified: 21 Nov 2024

    In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.

    Published: 9 Mar 2020
    6.5
    Medium

    CVE-2020-9282

    Last Modified: 21 Nov 2024

    In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing portfolios.

    Published: 9 Mar 2020
    4.8
    Medium

    CVE-2015-7343

    Last Modified: 21 Nov 2024

    JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.

    Published: 9 Mar 2020
    4.8
    Medium

    CVE-2015-7344

    Last Modified: 21 Nov 2024

    HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption].

    Published: 9 Mar 2020
    4.3
    Medium

    CVE-2015-7968

    Last Modified: 21 Nov 2024

    nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI.

    Published: 9 Mar 2020
    9.8
    Critical

    CVE-2019-20504

    Last Modified: 21 Nov 2024

    service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.

    Published: 9 Mar 2020
    7.2
    High

    CVE-2016-11021

    Last Modified: 5 Nov 2025

    setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.

    Published: 9 Mar 2020
    4.3
    Medium

    CVE-2019-10806

    Last Modified: 21 Nov 2024

    vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.

    Published: 9 Mar 2020
    5
    Medium

    CVE-2020-1753

    Last Modified: 21 Nov 2024

    A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are passed to kubectl from the command line, not using an environment variable or an input configuration file. This will disclose passwords and tokens from process list and no_log directive from debug module would not have any effect making these secrets being disclosed on stdout and log files.

    Published: 9 Mar 2020
    7.5
    High

    CVE-2020-10675

    Last Modified: 21 Nov 2024

    The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call.

    Published: 9 Mar 2020
    8.8
    High

    CVE-2020-2134

    Last Modified: 21 Nov 2024

    Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor bodies.

    Published: 9 Mar 2020
    8.8
    High

    CVE-2020-2135

    Last Modified: 21 Nov 2024

    Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable.

    Published: 9 Mar 2020
    5.4
    Medium

    CVE-2020-2136

    Last Modified: 21 Nov 2024

    Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.

    Published: 9 Mar 2020
    7.1
    High

    CVE-2020-2138

    Last Modified: 21 Nov 2024

    Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 9 Mar 2020
    6.5
    Medium

    CVE-2020-2139

    Last Modified: 21 Nov 2024

    An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.

    Published: 9 Mar 2020
    6.1
    Medium

    CVE-2020-2152

    Last Modified: 21 Nov 2024

    Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.

    Published: 9 Mar 2020
    9.8
    Critical

    CVE-2020-10232

    Last Modified: 21 Nov 2024

    In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.

    Published: 8 Mar 2020
    9.1
    Critical

    CVE-2020-10233

    Last Modified: 21 Nov 2024

    In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c.

    Published: 8 Mar 2020
    9.8
    Critical

    CVE-2020-10224

    Last Modified: 21 Nov 2024

    An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.

    Published: 8 Mar 2020
    9.8
    Critical

    CVE-2020-10225

    Last Modified: 21 Nov 2024

    An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.

    Published: 8 Mar 2020
    8.1
    High

    CVE-2020-10222

    Last Modified: 21 Nov 2024

    npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.

    Published: 8 Mar 2020
    8.1
    High

    CVE-2020-10223

    Last Modified: 21 Nov 2024

    npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe via a crafted PDF document.

    Published: 8 Mar 2020
    8.8
    High

    CVE-2020-10221

    Last Modified: 7 Nov 2025

    lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.

    Published: 8 Mar 2020
    9.8
    Critical

    CVE-2020-10220

    Last Modified: 21 Nov 2024

    An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.

    Published: 7 Mar 2020
    8.8
    High

    CVE-2020-10214

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary. It allows an authenticated user to execute arbitrary code via a POST to ntp_sync.cgi with a sufficiently long parameter ntp_server.

    Published: 7 Mar 2020
    8.8
    High

    CVE-2020-10215

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parameter in a dns_query.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.

    Published: 7 Mar 2020
    8.8
    High

    CVE-2020-10216

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a system_time.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.

    Published: 7 Mar 2020
    8.8
    High

    CVE-2020-10213

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin parameter in a set_sta_enrollee_pin.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.

    Published: 7 Mar 2020