2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36449HIGH8.1An issue was discovered in the kekbit crate before 0.3.4 for Rust. For ShmWriter<H>, Send is implemented without requiri...
CVE-2020-36448HIGH8.1An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send ...
CVE-2020-36447HIGH8.1An issue was discovered in the v9 crate through 2020-12-18 for Rust. There is an unconditional implementation of Sync fo...
CVE-2020-36446HIGH8.1An issue was discovered in the signal-simple crate through 2020-11-15 for Rust. There are unconditional implementations ...
CVE-2020-36445HIGH8.1An issue was discovered in the convec crate through 2020-11-24 for Rust. There are unconditional implementations of Send...
CVE-2020-36444HIGH8.1An issue was discovered in the async-coap crate through 2020-12-08 for Rust. Send and Sync are implemented for ArcGuard<...
CVE-2020-36443CRITICAL9.8An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust. An uninitialized buffer is passed to AsyncRe...
CVE-2020-36442HIGH8.1An issue was discovered in the beef crate before 0.5.0 for Rust. beef::Cow has no Sync bound on its Send trait.
CVE-2020-36441HIGH8.1An issue was discovered in the abox crate before 0.4.1 for Rust. It implements Send and Sync for AtomicBox<T> with no re...
CVE-2020-36440HIGH8.1An issue was discovered in the libsbc crate before 0.1.5 for Rust. For Decoder<R>, it implements Send for any R: Read.
CVE-2020-36439HIGH8.1An issue was discovered in the ticketed_lock crate before 0.3.0 for Rust. There are unconditional implementations of Sen...
CVE-2020-36438HIGH8.1An issue was discovered in the tiny_future crate before 0.4.0 for Rust. Future<T> does not have bounds on its Send and S...
CVE-2020-36437HIGH8.1An issue was discovered in the conqueue crate before 0.4.0 for Rust. There are unconditional implementations of Send and...
CVE-2020-36436HIGH8.1An issue was discovered in the unicycle crate before 0.7.1 for Rust. PinSlab<T> and Unordered<T, S> do not have bounds o...
CVE-2020-36435HIGH8.1An issue was discovered in the ruspiro-singleton crate before 0.4.1 for Rust. In Singleton, Send and Sync do not have bo...
CVE-2020-36434CRITICAL9.8An issue was discovered in the sys-info crate before 0.8.0 for Rust. sys_info::disk_info calls can trigger a double free...
CVE-2020-36433HIGH7.5An issue was discovered in the chunky crate through 2020-08-25 for Rust. The Chunk API does not honor an alignment requi...
CVE-2020-36432CRITICAL9.8An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matr...
CVE-2020-28088CRITICAL9.8An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execut...
CVE-2020-28087HIGH7.5A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sens...
CVE-2020-21358MEDIUM6.5A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attackers to arbitrarily add users.
CVE-2020-21357MEDIUM6.1A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to...
CVE-2020-21356MEDIUM5.3An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host whe...
CVE-2020-21353MEDIUM5.4A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to exe...
CVE-2020-18694HIGH8.8Cross Site Request Forgery (CSRF) in IgnitedCMS v1.0 allows remote attackers to obtain sensitive information and gain pr...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now