2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-18693 | MEDIUM | 5.4 | 1.0% | Aug 6, 2021 | Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious... |
| CVE-2020-22330 | MEDIUM | 6.1 | 0.6% | Aug 6, 2021 | Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page. |
| CVE-2020-22392 | MEDIUM | 5.4 | 0.6% | Aug 5, 2021 | Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file. |
| CVE-2020-7863 | HIGH | 8.8 | 1.5% | Aug 5, 2021 | A vulnerability in File Transfer Solution of Raonwiz could allow arbitrary command execution as the result of viewing a ... |
| CVE-2020-22732 | MEDIUM | 4.8 | 0.5% | Aug 5, 2021 | CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker.. |
| CVE-2020-24829 | MEDIUM | 5.5 | 1.0% | Aug 4, 2021 | An issue was discovered in GPAC from v0.5.2 to v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overfl... |
| CVE-2020-22352 | MEDIUM | 5.5 | 0.7% | Aug 4, 2021 | The gf_dash_segmenter_probe_input function in GPAC v0.8 allows attackers to cause a denial of service (NULL pointer dere... |
| CVE-2020-29011 | HIGH | 8.8 | 1.0% | Aug 4, 2021 | Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox 3.2.0 throu... |
| CVE-2020-24827 | MEDIUM | 5.5 | 0.7% | Aug 4, 2021 | A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service ... |
| CVE-2020-24826 | MEDIUM | 5.5 | 0.7% | Aug 4, 2021 | A vulnerability in the elf::section::as_strtab function of Libelfin v0.3 allows attackers to cause a denial of service (... |
| CVE-2020-24825 | MEDIUM | 5.5 | 0.7% | Aug 4, 2021 | A vulnerability in the line_table::line_table function of Libelfin v0.3 allows attackers to cause a denial of service (D... |
| CVE-2020-24824 | MEDIUM | 5.5 | 0.7% | Aug 4, 2021 | A global buffer overflow issue in the dwarf::line_table::line_table function of Libelfin v0.3 allows attackers to cause ... |
| CVE-2020-24823 | MEDIUM | 5.5 | 0.7% | Aug 4, 2021 | A vulnerability in the dwarf::to_string function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) th... |
| CVE-2020-24822 | MEDIUM | 5.5 | 0.7% | Aug 4, 2021 | A vulnerability in the dwarf::cursor::uleb function of Libelfin v0.3 allows attackers to cause a denial of service (DOS)... |
| CVE-2020-24821 | MEDIUM | 5.5 | 0.7% | Aug 4, 2021 | A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service ... |
| CVE-2020-4707 | MEDIUM | 5.4 | 0.5% | Aug 4, 2021 | IBM API Connect 5.0.0.0 through 5.0.8.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2020-19305 | CRITICAL | 9.8 | 2.1% | Aug 3, 2021 | An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when ... |
| CVE-2020-19304 | HIGH | 7.5 | 1.9% | Aug 3, 2021 | An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory... |
| CVE-2020-19303 | HIGH | 7.8 | 1.3% | Aug 3, 2021 | An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a ... |
| CVE-2020-19302 | CRITICAL | 9.8 | 1.7% | Aug 3, 2021 | An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a websh... |
| CVE-2020-19301 | CRITICAL | 9.8 | 2.5% | Aug 3, 2021 | A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a... |
| CVE-2020-26806 | HIGH | 8.8 | 6.0% | Jul 31, 2021 | admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in r... |
| CVE-2020-26565 | HIGH | 7.5 | 1.7% | Jul 31, 2021 | ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. Thi... |
| CVE-2020-26564 | MEDIUM | 6.5 | 1.1% | Jul 31, 2021 | ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create ... |
| CVE-2020-26563 | MEDIUM | 6.1 | 1.0% | Jul 30, 2021 | ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query st... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now