2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-5955CRITICAL9.8An issue was discovered in Int15MicrocodeSmm in Insyde InsydeH2O before 2021-10-14 on Intel client chipsets. A caller ma...
CVE-2020-27820MEDIUM4.7A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if remo...
CVE-2020-6492CRITICAL9.6Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbo...
CVE-2020-16048MEDIUM6.5Out of bounds read in ANGLE allowed a remote attacker to obtain sensitive data via a crafted HTML page.
CVE-2020-15935MEDIUM4.3A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a re...
CVE-2020-23754CRITICAL9.6Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows att...
CVE-2020-23719CRITICAL9.6Cross site scripting (XSS) vulnerability in application/controllers/AdminController.php in xujinliang zibbs 1.0, allows ...
CVE-2020-23718CRITICAL9.6Cross site scripting (XSS) vulnerability in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the rou...
CVE-2020-23686HIGH8.8Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or...
CVE-2020-23685CRITICAL9.8SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privile...
CVE-2020-21574HIGH7.5Buffer overflow vulnerability in YotsuyaNight c-http v0.1.0, allows attackers to cause a denial of service via a long ur...
CVE-2020-21573MEDIUM5.5An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of ser...
CVE-2020-21572HIGH7.5Buffer overflow vulnerability in function src_parser_trans_stage_1_2_3 trgil gilcc before commit 803969389ca9c06237075a7...
CVE-2020-20658HIGH7.5Buffer overflow vulnerability in fcovatti libiec_iccp_mod v1.5, allows attackers to cause a denail of service when tryin...
CVE-2020-20657HIGH7.5Buffer overflow vulnerability in fcovatti libiec_iccp_mod v1.5, allows attackers to cause a denial of service via an une...
CVE-2020-18440CRITICAL9.8Buffer overflow vulnerability in framework/init.php in qinggan phpok 5.1, allows attackers to execute arbitrary code.
CVE-2020-18439CRITICAL9.1An issue was discoverered in in function edit_save_f in framework/admin/tpl_control.php in qinggan phpok 5.1, allows att...
CVE-2020-18438HIGH7.5Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the titl...
CVE-2020-15940MEDIUM5.4An improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and belo...
CVE-2020-12814MEDIUM5.4A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiAnalyzer version...
CVE-2020-35249MEDIUM6.1Cross Site Scripting (XSS) vulnerability in ElkarBackup 1.3.3, allows attackers to execute arbitrary code via the name p...
CVE-2020-27406MEDIUM5.4Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via th...
CVE-2020-28702HIGH7.5A SQL injection vulnerability in TopicMapper.xml of PybbsCMS v5.2.1 allows attackers to access sensitive database inform...
CVE-2020-36505MEDIUM6.5The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which c...
CVE-2020-36504MEDIUM6.5The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now