2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-21531MEDIUM5.5fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.
CVE-2020-21530MEDIUM5.5fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c.
CVE-2020-21529MEDIUM5.5fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c.
CVE-2020-14124CRITICAL9.8There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router ...
CVE-2020-14119CRITICAL9.8There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under adminis...
CVE-2020-14130MEDIUM5.3Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi ...
CVE-2020-14109HIGH7.2There is command injection in the meshd program in the routing system, resulting in command execution under administrato...
CVE-2020-21483HIGH7.2An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg fi...
CVE-2020-21482MEDIUM5.4A cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a cr...
CVE-2020-21481HIGH7.2An arbitrary file upload vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted .txt file...
CVE-2020-21480HIGH7.2An arbitrary file write vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2020-21322CRITICAL9.8An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a cr...
CVE-2020-21321MEDIUM4.3emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to ar...
CVE-2020-21127CRITICAL9.8MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.
CVE-2020-21126HIGH8.8MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo.
CVE-2020-21125CRITICAL9.8An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code.
CVE-2020-21124CRITICAL9.8UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.
CVE-2020-21122MEDIUM5.3UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intra...
CVE-2020-21121CRITICAL9.8Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_m...
CVE-2020-19159HIGH8.8Cross Site Request Forgery (CSRF) in LaikeTui v3 allows remote attackers to execute arbitrary code via the component '/i...
CVE-2020-19158MEDIUM5.4Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the...
CVE-2020-19157MEDIUM6.1Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter...
CVE-2020-19156MEDIUM5.4Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter...
CVE-2020-19155HIGH8.8Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or ...
CVE-2020-19154MEDIUM6.5Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now