2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-21359 | CRITICAL | 9.8 | 1.7% | Aug 11, 2021 | An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix wh... |
| CVE-2020-21976 | HIGH | 8.8 | 1.8% | Aug 11, 2021 | An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers t... |
| CVE-2020-28589 | HIGH | 8.8 | 1.9% | Aug 11, 2021 | An improper array index validation vulnerability exists in the LoadObj functionality of tinyobjloader v2.0-rc1 and tinyo... |
| CVE-2020-21930 | MEDIUM | 5.4 | 0.5% | Aug 10, 2021 | A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attacke... |
| CVE-2020-21929 | MEDIUM | 5.4 | 0.5% | Aug 10, 2021 | A stored cross site scripting (XSS) vulnerability in the web_copyright field of Eyoucms v1.4.1 allows authenticated atta... |
| CVE-2020-21697 | MEDIUM | 6.5 | 0.9% | Aug 10, 2021 | A heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a den... |
| CVE-2020-21690 | — | — | — | Aug 10, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-20451. Reason: This candidate is a duplicate of ... |
| CVE-2020-21688 | HIGH | 8.8 | 1.7% | Aug 10, 2021 | A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary co... |
| CVE-2020-21684 | MEDIUM | 5.5 | 0.8% | Aug 10, 2021 | A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service ... |
| CVE-2020-21683 | MEDIUM | 5.5 | 0.8% | Aug 10, 2021 | A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attacke... |
| CVE-2020-21682 | MEDIUM | 5.5 | 0.9% | Aug 10, 2021 | A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of se... |
| CVE-2020-21681 | MEDIUM | 5.5 | 0.8% | Aug 10, 2021 | A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of s... |
| CVE-2020-21680 | MEDIUM | 5.5 | 0.7% | Aug 10, 2021 | A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a ... |
| CVE-2020-21678 | MEDIUM | 5.5 | 0.8% | Aug 10, 2021 | A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to ca... |
| CVE-2020-21677 | MEDIUM | 6.5 | 0.9% | Aug 10, 2021 | A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows at... |
| CVE-2020-21676 | MEDIUM | 5.5 | 1.1% | Aug 10, 2021 | A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to ca... |
| CVE-2020-21675 | MEDIUM | 5.5 | 1.1% | Aug 10, 2021 | A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a den... |
| CVE-2020-25082 | LOW | 3.8 | 0.2% | Aug 10, 2021 | An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elli... |
| CVE-2020-23172 | MEDIUM | 5.5 | 0.7% | Aug 10, 2021 | A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with craf... |
| CVE-2020-23171 | MEDIUM | 5.5 | 0.7% | Aug 10, 2021 | A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via... |
| CVE-2020-28397 | MEDIUM | 5.3 | 0.8% | Aug 10, 2021 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Co... |
| CVE-2020-23151 | CRITICAL | 9.8 | 5.7% | Aug 9, 2021 | rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since t... |
| CVE-2020-23150 | HIGH | 7.5 | 1.6% | Aug 9, 2021 | A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database informati... |
| CVE-2020-23149 | HIGH | 7.5 | 1.4% | Aug 9, 2021 | The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection... |
| CVE-2020-23148 | HIGH | 7.5 | 1.6% | Aug 9, 2021 | The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injectio... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now