2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-19287MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execu...
CVE-2020-19286MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to ...
CVE-2020-19285MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to exec...
CVE-2020-19284MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to ex...
CVE-2020-19283MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to ex...
CVE-2020-19282MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts o...
CVE-2020-19281MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attacker...
CVE-2020-19280HIGH8.8Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sens...
CVE-2020-19268MEDIUM5.7A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to a...
CVE-2020-19267CRITICAL9.8An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading ...
CVE-2020-19266MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Site/articleList component of Dswjcms 1.6.4 a...
CVE-2020-19265MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Basis/links component of Dswjcms 1.6.4 allows...
CVE-2020-19264MEDIUM6.5A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily add users via index.php?s=/user/Api...
CVE-2020-19263HIGH8.8A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily escalate user privileges to adminis...
CVE-2020-19515MEDIUM6.1qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
CVE-2020-19144MEDIUM6.5Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the...
CVE-2020-19143MEDIUM6.5Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the ...
CVE-2020-7874HIGH8.8Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows ...
CVE-2020-7873CRITICAL9.8Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to...
CVE-2020-26300CRITICAL9.8systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation be...
CVE-2020-26772CRITICAL9.8Command Injection in PPGo_Jobs v2.8.0 allows remote attackers to execute arbitrary code via the 'AjaxRun()' function.
CVE-2020-19138CRITICAL9.8Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary...
CVE-2020-19137HIGH7.5Incorrect Access Control in Autumn v1.0.4 and earlier allows remote attackers to obtain clear-text login credentials via...
CVE-2020-24672CRITICAL9.8A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer runni...
CVE-2020-27942HIGH7.8A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Se...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now