2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27464 | HIGH | 7.8 | 2.5% | Aug 20, 2021 | An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrar... |
| CVE-2020-27461 | HIGH | 8.8 | 3.7% | Aug 20, 2021 | A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote ... |
| CVE-2020-25359 | CRITICAL | 9.1 | 2.3% | Aug 20, 2021 | An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers th... |
| CVE-2020-25353 | MEDIUM | 6.5 | 1.0% | Aug 20, 2021 | A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed... |
| CVE-2020-25352 | MEDIUM | 5.4 | 2.0% | Aug 20, 2021 | A stored cross-site scripting (XSS) vulnerability in the /devices.php function inrConfig 3.9.5 has been fixed for versio... |
| CVE-2020-25351 | MEDIUM | 6.5 | 1.1% | Aug 20, 2021 | An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed re... |
| CVE-2020-36474 | CRITICAL | 9.8 | 1.8% | Aug 20, 2021 | SafeCurl before 0.9.2 has a DNS rebinding vulnerability. |
| CVE-2020-18886 | HIGH | 7.2 | 1.8% | Aug 20, 2021 | Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/up... |
| CVE-2020-18885 | HIGH | 7.2 | 3.9% | Aug 20, 2021 | Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the ... |
| CVE-2020-18879 | CRITICAL | 9.8 | 3.1% | Aug 20, 2021 | Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files... |
| CVE-2020-18878 | MEDIUM | 5.3 | 2.0% | Aug 20, 2021 | Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.ph... |
| CVE-2020-18877 | HIGH | 7.5 | 1.5% | Aug 20, 2021 | SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in th... |
| CVE-2020-18900 | LOW | 3.3 | 0.3% | Aug 19, 2021 | A heap-based buffer overflow in the libexe_io_handle_read_coff_optional_header function of libyal libexe before 20181128... |
| CVE-2020-18899 | MEDIUM | 6.5 | 1.7% | Aug 19, 2021 | An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to c... |
| CVE-2020-18898 | MEDIUM | 6.5 | 1.4% | Aug 19, 2021 | A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of se... |
| CVE-2020-18897 | HIGH | 7.8 | 0.5% | Aug 19, 2021 | An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows att... |
| CVE-2020-20645 | MEDIUM | 5.4 | 0.5% | Aug 19, 2021 | Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area. |
| CVE-2020-20642 | HIGH | 8.8 | 0.6% | Aug 19, 2021 | Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code ... |
| CVE-2020-18748 | MEDIUM | 6.1 | 0.9% | Aug 19, 2021 | Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a math... |
| CVE-2020-35685 | CRITICAL | 9.1 | 2.1% | Aug 19, 2021 | An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connectio... |
| CVE-2020-35684 | HIGH | 7.5 | 2.3% | Aug 19, 2021 | An issue was discovered in HCC Nichestack 3.0. The code that parses TCP packets relies on an unchecked value of the IP p... |
| CVE-2020-35683 | HIGH | 7.5 | 2.3% | Aug 19, 2021 | An issue was discovered in HCC Nichestack 3.0. The code that parses ICMP packets relies on an unchecked value of the IP ... |
| CVE-2020-22345 | HIGH | 8.8 | 3.8% | Aug 18, 2021 | /graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via s... |
| CVE-2020-25928 | CRITICAL | 9.8 | 3.6% | Aug 18, 2021 | The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary ... |
| CVE-2020-25927 | HIGH | 7.5 | 2.3% | Aug 18, 2021 | The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Out-of-bounds Read. The impact is: a denial of ser... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now