2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4706 | MEDIUM | 5.4 | 0.9% | Aug 17, 2021 | IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by improper validation of input ... |
| CVE-2020-18705 | CRITICAL | 9.8 | 2.8% | Aug 16, 2021 | XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka... |
| CVE-2020-18704 | CRITICAL | 9.8 | 2.9% | Aug 16, 2021 | Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code... |
| CVE-2020-18703 | CRITICAL | 9.8 | 2.8% | Aug 16, 2021 | XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka... |
| CVE-2020-18702 | MEDIUM | 6.1 | 1.3% | Aug 16, 2021 | Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' paramet... |
| CVE-2020-18701 | CRITICAL | 9.8 | 2.3% | Aug 16, 2021 | Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain pri... |
| CVE-2020-18699 | MEDIUM | 6.1 | 1.3% | Aug 16, 2021 | Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts... |
| CVE-2020-18698 | CRITICAL | 9.8 | 2.0% | Aug 16, 2021 | Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without res... |
| CVE-2020-36473 | LOW | 3.7 | 0.5% | Aug 14, 2021 | UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visite... |
| CVE-2020-21066 | MEDIUM | 6.5 | 0.8% | Aug 13, 2021 | An issue was discovered in Bento4 v1.5.1.0. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom... |
| CVE-2020-21064 | — | — | — | Aug 13, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15048. Reason: This candidate is a reservation d... |
| CVE-2020-18759 | HIGH | 7.5 | 0.8% | Aug 13, 2021 | An information disclosure vulnerability exists in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100... |
| CVE-2020-18758 | CRITICAL | 9.8 | 2.7% | Aug 13, 2021 | An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code. |
| CVE-2020-18757 | HIGH | 7.5 | 1.3% | Aug 13, 2021 | An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (D... |
| CVE-2020-18756 | HIGH | 7.5 | 1.3% | Aug 13, 2021 | An arbitrary memory access vulnerability in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100 allow... |
| CVE-2020-18754 | HIGH | 7.5 | 1.3% | Aug 13, 2021 | An information disclosure vulnerability exists within Dut Computer Control Engineering Co.'s PLC MAC1100. |
| CVE-2020-18753 | CRITICAL | 9.8 | 1.5% | Aug 13, 2021 | An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalat... |
| CVE-2020-36363 | CRITICAL | 9.8 | 0.7% | Aug 12, 2021 | Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA38... |
| CVE-2020-22403 | HIGH | 8.8 | 0.6% | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account... |
| CVE-2020-20990 | MEDIUM | 5.4 | 0.6% | Aug 12, 2021 | A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to exe... |
| CVE-2020-20989 | MEDIUM | 4.3 | 0.5% | Aug 12, 2021 | A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs... |
| CVE-2020-20988 | MEDIUM | 5.4 | 1.3% | Aug 12, 2021 | A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attacker... |
| CVE-2020-18464 | LOW | 3.5 | 0.3% | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability in AikCms 2.0.0 in video_list.php, which can let a malicious user delete... |
| CVE-2020-18463 | LOW | 2.4 | 0.3% | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability exists in v2.0.0 in video_list.php, which can let a malicious user delet... |
| CVE-2020-18462 | HIGH | 7.2 | 1.0% | Aug 12, 2021 | File Upload vulnerabilty in AikCms v2.0.0 in poster_edit.php because the background file management office does not veri... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now