2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-21531 | MEDIUM | 5.5 | 1.0% | Sep 16, 2021 | fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c. |
| CVE-2020-21530 | MEDIUM | 5.5 | 0.7% | Sep 16, 2021 | fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c. |
| CVE-2020-21529 | MEDIUM | 5.5 | 1.1% | Sep 16, 2021 | fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c. |
| CVE-2020-14124 | CRITICAL | 9.8 | 1.9% | Sep 16, 2021 | There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router ... |
| CVE-2020-14119 | CRITICAL | 9.8 | 3.0% | Sep 16, 2021 | There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under adminis... |
| CVE-2020-14130 | MEDIUM | 5.3 | 0.7% | Sep 16, 2021 | Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi ... |
| CVE-2020-14109 | HIGH | 7.2 | 2.2% | Sep 16, 2021 | There is command injection in the meshd program in the routing system, resulting in command execution under administrato... |
| CVE-2020-21483 | HIGH | 7.2 | 1.6% | Sep 15, 2021 | An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg fi... |
| CVE-2020-21482 | MEDIUM | 5.4 | 0.6% | Sep 15, 2021 | A cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a cr... |
| CVE-2020-21481 | HIGH | 7.2 | 1.6% | Sep 15, 2021 | An arbitrary file upload vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted .txt file... |
| CVE-2020-21480 | HIGH | 7.2 | 1.6% | Sep 15, 2021 | An arbitrary file write vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted PHP file. |
| CVE-2020-21322 | CRITICAL | 9.8 | 1.7% | Sep 15, 2021 | An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a cr... |
| CVE-2020-21321 | MEDIUM | 4.3 | 0.5% | Sep 15, 2021 | emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to ar... |
| CVE-2020-21127 | CRITICAL | 9.8 | 1.6% | Sep 15, 2021 | MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel. |
| CVE-2020-21126 | HIGH | 8.8 | 0.6% | Sep 15, 2021 | MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo. |
| CVE-2020-21125 | CRITICAL | 9.8 | 1.7% | Sep 15, 2021 | An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code. |
| CVE-2020-21124 | CRITICAL | 9.8 | 2.1% | Sep 15, 2021 | UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page. |
| CVE-2020-21122 | MEDIUM | 5.3 | 0.8% | Sep 15, 2021 | UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intra... |
| CVE-2020-21121 | CRITICAL | 9.8 | 1.1% | Sep 15, 2021 | Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_m... |
| CVE-2020-19159 | HIGH | 8.8 | 1.0% | Sep 15, 2021 | Cross Site Request Forgery (CSRF) in LaikeTui v3 allows remote attackers to execute arbitrary code via the component '/i... |
| CVE-2020-19158 | MEDIUM | 5.4 | 0.7% | Sep 15, 2021 | Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the... |
| CVE-2020-19157 | MEDIUM | 6.1 | 1.0% | Sep 15, 2021 | Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter... |
| CVE-2020-19156 | MEDIUM | 5.4 | 0.8% | Sep 15, 2021 | Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter... |
| CVE-2020-19155 | HIGH | 8.8 | 7.3% | Sep 15, 2021 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or ... |
| CVE-2020-19154 | MEDIUM | 6.5 | 3.6% | Sep 15, 2021 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now