2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36503 | HIGH | 8 | 1.2% | Nov 1, 2021 | The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, w... |
| CVE-2020-36381 | CRITICAL | 9.8 | 1.8% | Oct 31, 2021 | An issue was discovered in the singleCrunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary cod... |
| CVE-2020-36380 | CRITICAL | 9.8 | 2.1% | Oct 31, 2021 | An issue was discovered in the crunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via ... |
| CVE-2020-36379 | CRITICAL | 9.8 | 1.8% | Oct 31, 2021 | An issue was discovered in the remove function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via ... |
| CVE-2020-36378 | CRITICAL | 9.8 | 1.8% | Oct 31, 2021 | An issue was discovered in the packageCmd function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code ... |
| CVE-2020-36377 | CRITICAL | 9.8 | 1.8% | Oct 31, 2021 | An issue was discovered in the dump function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via th... |
| CVE-2020-36376 | CRITICAL | 9.8 | 1.8% | Oct 31, 2021 | An issue was discovered in the list function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via th... |
| CVE-2020-26707 | CRITICAL | 9.8 | 1.8% | Oct 31, 2021 | An issue was discovered in the add function in Shenzhim AAPTJS 1.3.1 which allows attackers to execute arbitrary code vi... |
| CVE-2020-26705 | CRITICAL | 9.1 | 1.3% | Oct 31, 2021 | The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows fo... |
| CVE-2020-25912 | CRITICAL | 9.1 | 1.4% | Oct 31, 2021 | A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10... |
| CVE-2020-25911 | CRITICAL | 9.1 | 2.3% | Oct 31, 2021 | A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which ... |
| CVE-2020-25881 | MEDIUM | 5.5 | 1.2% | Oct 29, 2021 | A vulnerability was discovered in the filename parameter in pathindex.php?r=cms-backend/attachment/delete&sub=&filename=... |
| CVE-2020-25873 | MEDIUM | 6.5 | 1.1% | Oct 29, 2021 | A directory traversal vulnerability in the component system/manager/class/web/database.php was discovered in Baijiacms V... |
| CVE-2020-25872 | MEDIUM | 4.9 | 1.1% | Oct 29, 2021 | A vulnerability exists within the FileManagerController.php function in FrogCMS 0.9.5 which allows an attacker to perfor... |
| CVE-2020-22079 | CRITICAL | 9.8 | 4.0% | Oct 29, 2021 | Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attacke... |
| CVE-2020-23549 | HIGH | 7.8 | 0.9% | Oct 28, 2021 | IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted .cr2 fi... |
| CVE-2020-23546 | HIGH | 7.8 | 1.0% | Oct 28, 2021 | IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted XBM fil... |
| CVE-2020-9897 | HIGH | 7.8 | 0.9% | Oct 28, 2021 | An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, ma... |
| CVE-2020-29629 | MEDIUM | 5.5 | 0.6% | Oct 28, 2021 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. A malic... |
| CVE-2020-25422 | MEDIUM | 5.4 | 0.5% | Oct 28, 2021 | A cross site scripting (XSS) vulnerability in menuedit.php of Mara CMS 7.5 allows attackers to execute arbitrary web scr... |
| CVE-2020-10005 | MEDIUM | 6.5 | 1.3% | Oct 28, 2021 | A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. A... |
| CVE-2020-7875 | HIGH | 8.8 | 0.6% | Oct 28, 2021 | DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and e... |
| CVE-2020-22312 | MEDIUM | 6.1 | 0.7% | Oct 28, 2021 | A cross-site scripting (XSS) vulnerability was discovered in the OJ/admin-tool /cal_scores.php function of HZNUOJ v1.0. |
| CVE-2020-21250 | CRITICAL | 9.8 | 1.1% | Oct 27, 2021 | CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php. |
| CVE-2020-24932 | CRITICAL | 9.8 | 1.6% | Oct 27, 2021 | An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complai... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now