2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-21359CRITICAL9.8An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix wh...
CVE-2020-21976HIGH8.8An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers t...
CVE-2020-28589HIGH8.8An improper array index validation vulnerability exists in the LoadObj functionality of tinyobjloader v2.0-rc1 and tinyo...
CVE-2020-21930MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attacke...
CVE-2020-21929MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the web_copyright field of Eyoucms v1.4.1 allows authenticated atta...
CVE-2020-21697MEDIUM6.5A heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a den...
CVE-2020-21690Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-20451. Reason: This candidate is a duplicate of ...
CVE-2020-21688HIGH8.8A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary co...
CVE-2020-21684MEDIUM5.5A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service ...
CVE-2020-21683MEDIUM5.5A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attacke...
CVE-2020-21682MEDIUM5.5A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of se...
CVE-2020-21681MEDIUM5.5A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of s...
CVE-2020-21680MEDIUM5.5A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a ...
CVE-2020-21678MEDIUM5.5A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to ca...
CVE-2020-21677MEDIUM6.5A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows at...
CVE-2020-21676MEDIUM5.5A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to ca...
CVE-2020-21675MEDIUM5.5A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a den...
CVE-2020-25082LOW3.8An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elli...
CVE-2020-23172MEDIUM5.5A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with craf...
CVE-2020-23171MEDIUM5.5A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via...
CVE-2020-28397MEDIUM5.3A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Co...
CVE-2020-23151CRITICAL9.8rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since t...
CVE-2020-23150HIGH7.5A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database informati...
CVE-2020-23149HIGH7.5The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection...
CVE-2020-23148HIGH7.5The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injectio...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now