2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36503HIGH8The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, w...
CVE-2020-36381CRITICAL9.8An issue was discovered in the singleCrunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary cod...
CVE-2020-36380CRITICAL9.8An issue was discovered in the crunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via ...
CVE-2020-36379CRITICAL9.8An issue was discovered in the remove function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via ...
CVE-2020-36378CRITICAL9.8An issue was discovered in the packageCmd function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code ...
CVE-2020-36377CRITICAL9.8An issue was discovered in the dump function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via th...
CVE-2020-36376CRITICAL9.8An issue was discovered in the list function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via th...
CVE-2020-26707CRITICAL9.8An issue was discovered in the add function in Shenzhim AAPTJS 1.3.1 which allows attackers to execute arbitrary code vi...
CVE-2020-26705CRITICAL9.1The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows fo...
CVE-2020-25912CRITICAL9.1A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10...
CVE-2020-25911CRITICAL9.1A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which ...
CVE-2020-25881MEDIUM5.5A vulnerability was discovered in the filename parameter in pathindex.php?r=cms-backend/attachment/delete&sub=&filename=...
CVE-2020-25873MEDIUM6.5A directory traversal vulnerability in the component system/manager/class/web/database.php was discovered in Baijiacms V...
CVE-2020-25872MEDIUM4.9A vulnerability exists within the FileManagerController.php function in FrogCMS 0.9.5 which allows an attacker to perfor...
CVE-2020-22079CRITICAL9.8Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attacke...
CVE-2020-23549HIGH7.8IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted .cr2 fi...
CVE-2020-23546HIGH7.8IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted XBM fil...
CVE-2020-9897HIGH7.8An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, ma...
CVE-2020-29629MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. A malic...
CVE-2020-25422MEDIUM5.4A cross site scripting (XSS) vulnerability in menuedit.php of Mara CMS 7.5 allows attackers to execute arbitrary web scr...
CVE-2020-10005MEDIUM6.5A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. A...
CVE-2020-7875HIGH8.8DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and e...
CVE-2020-22312MEDIUM6.1A cross-site scripting (XSS) vulnerability was discovered in the OJ/admin-tool /cal_scores.php function of HZNUOJ v1.0.
CVE-2020-21250CRITICAL9.8CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
CVE-2020-24932CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complai...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now