2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-27464HIGH7.8An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrar...
CVE-2020-27461HIGH8.8A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote ...
CVE-2020-25359CRITICAL9.1An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers th...
CVE-2020-25353MEDIUM6.5A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed...
CVE-2020-25352MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the /devices.php function inrConfig 3.9.5 has been fixed for versio...
CVE-2020-25351MEDIUM6.5An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed re...
CVE-2020-36474CRITICAL9.8SafeCurl before 0.9.2 has a DNS rebinding vulnerability.
CVE-2020-18886HIGH7.2Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/up...
CVE-2020-18885HIGH7.2Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the ...
CVE-2020-18879CRITICAL9.8Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files...
CVE-2020-18878MEDIUM5.3Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.ph...
CVE-2020-18877HIGH7.5SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in th...
CVE-2020-18900LOW3.3A heap-based buffer overflow in the libexe_io_handle_read_coff_optional_header function of libyal libexe before 20181128...
CVE-2020-18899MEDIUM6.5An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to c...
CVE-2020-18898MEDIUM6.5A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of se...
CVE-2020-18897HIGH7.8An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows att...
CVE-2020-20645MEDIUM5.4Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.
CVE-2020-20642HIGH8.8Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code ...
CVE-2020-18748MEDIUM6.1Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a math...
CVE-2020-35685CRITICAL9.1An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connectio...
CVE-2020-35684HIGH7.5An issue was discovered in HCC Nichestack 3.0. The code that parses TCP packets relies on an unchecked value of the IP p...
CVE-2020-35683HIGH7.5An issue was discovered in HCC Nichestack 3.0. The code that parses ICMP packets relies on an unchecked value of the IP ...
CVE-2020-22345HIGH8.8/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via s...
CVE-2020-25928CRITICAL9.8The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary ...
CVE-2020-25927HIGH7.5The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Out-of-bounds Read. The impact is: a denial of ser...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now