2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-19151HIGH8.8Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a mali...
CVE-2020-19150HIGH8.1Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or caus...
CVE-2020-19148MEDIUM5.4Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'N...
CVE-2020-19147MEDIUM6.5Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the...
CVE-2020-19146MEDIUM6.5Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the...
CVE-2020-3960HIGH8.4VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and...
CVE-2020-35340HIGH7.5A local file inclusion vulnerability in ExpertPDF 9.5.0 through 14.1.0 allows attackers to read the file contents from f...
CVE-2020-21082MEDIUM6.1A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allow...
CVE-2020-21081MEDIUM6.5A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowled...
CVE-2020-21050MEDIUM6.5Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.
CVE-2020-21049MEDIUM6.5An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (...
CVE-2020-21048MEDIUM6.5An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a...
CVE-2020-20672HIGH7.8An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a cr...
CVE-2020-20671HIGH8.8A cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account.
CVE-2020-20670HIGH8.8An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary co...
CVE-2020-27970MEDIUM5.3Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar
CVE-2020-27969HIGH7.3Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing
CVE-2020-19295MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to e...
CVE-2020-19294MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to ...
CVE-2020-19293MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to exec...
CVE-2020-19292MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to exe...
CVE-2020-19291MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers t...
CVE-2020-19290MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to ex...
CVE-2020-19289MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attacker...
CVE-2020-19288MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to exec...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now