2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-19703 | MEDIUM | 6.1 | 0.7% | Aug 26, 2021 | A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitr... |
| CVE-2020-19547 | MEDIUM | 6.5 | 1.2% | Aug 25, 2021 | Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php. |
| CVE-2020-18065 | MEDIUM | 5.4 | 0.5% | Aug 25, 2021 | Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu. |
| CVE-2020-18976 | MEDIUM | 5.5 | 0.7% | Aug 25, 2021 | Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'che... |
| CVE-2020-18974 | LOW | 3.3 | 0.8% | Aug 25, 2021 | Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the c... |
| CVE-2020-18972 | MEDIUM | 5.5 | 0.8% | Aug 25, 2021 | Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive informa... |
| CVE-2020-18971 | MEDIUM | 5.5 | 0.7% | Aug 25, 2021 | Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/P... |
| CVE-2020-18917 | HIGH | 8.8 | 0.8% | Aug 24, 2021 | The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename ... |
| CVE-2020-18913 | HIGH | 7.5 | 1.3% | Aug 24, 2021 | EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via th... |
| CVE-2020-18778 | MEDIUM | 6.5 | 0.9% | Aug 23, 2021 | In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to... |
| CVE-2020-18776 | MEDIUM | 6.5 | 0.9% | Aug 23, 2021 | In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause de... |
| CVE-2020-18775 | MEDIUM | 6.5 | 0.9% | Aug 23, 2021 | In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to... |
| CVE-2020-18774 | MEDIUM | 6.5 | 1.3% | Aug 23, 2021 | A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial ... |
| CVE-2020-18773 | MEDIUM | 6.5 | 1.3% | Aug 23, 2021 | An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of ser... |
| CVE-2020-18771 | HIGH | 8.1 | 1.8% | Aug 23, 2021 | Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which ... |
| CVE-2020-18735 | HIGH | 7.5 | 1.9% | Aug 23, 2021 | A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server t... |
| CVE-2020-18734 | HIGH | 7.5 | 1.9% | Aug 23, 2021 | A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server t... |
| CVE-2020-18731 | HIGH | 7.5 | 1.4% | Aug 23, 2021 | A segmentation violation in the Iec104_Deal_FirmUpdate function of IEC104 v1.0 allows attackers to cause a denial of ser... |
| CVE-2020-18730 | HIGH | 7.5 | 1.4% | Aug 23, 2021 | A segmentation violation in the Iec104_Deal_I function of IEC104 v1.0 allows attackers to cause a denial of service (DOS... |
| CVE-2020-36478 | HIGH | 7.5 | 1.1% | Aug 23, 2021 | An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parame... |
| CVE-2020-36477 | MEDIUM | 5.9 | 0.8% | Aug 23, 2021 | An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected com... |
| CVE-2020-36476 | HIGH | 7.5 | 1.4% | Aug 23, 2021 | An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroiz... |
| CVE-2020-36475 | HIGH | 7.5 | 1.8% | Aug 23, 2021 | An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations perfor... |
| CVE-2020-24130 | HIGH | 8.1 | 0.4% | Aug 20, 2021 | A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to ch... |
| CVE-2020-27466 | HIGH | 7.8 | 1.9% | Aug 20, 2021 | An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to exec... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now