2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-18693MEDIUM5.4Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious...
CVE-2020-22330MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.
CVE-2020-22392MEDIUM5.4Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.
CVE-2020-7863HIGH8.8A vulnerability in File Transfer Solution of Raonwiz could allow arbitrary command execution as the result of viewing a ...
CVE-2020-22732MEDIUM4.8CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..
CVE-2020-24829MEDIUM5.5An issue was discovered in GPAC from v0.5.2 to v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overfl...
CVE-2020-22352MEDIUM5.5The gf_dash_segmenter_probe_input function in GPAC v0.8 allows attackers to cause a denial of service (NULL pointer dere...
CVE-2020-29011HIGH8.8Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox 3.2.0 throu...
CVE-2020-24827MEDIUM5.5A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service ...
CVE-2020-24826MEDIUM5.5A vulnerability in the elf::section::as_strtab function of Libelfin v0.3 allows attackers to cause a denial of service (...
CVE-2020-24825MEDIUM5.5A vulnerability in the line_table::line_table function of Libelfin v0.3 allows attackers to cause a denial of service (D...
CVE-2020-24824MEDIUM5.5A global buffer overflow issue in the dwarf::line_table::line_table function of Libelfin v0.3 allows attackers to cause ...
CVE-2020-24823MEDIUM5.5A vulnerability in the dwarf::to_string function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) th...
CVE-2020-24822MEDIUM5.5A vulnerability in the dwarf::cursor::uleb function of Libelfin v0.3 allows attackers to cause a denial of service (DOS)...
CVE-2020-24821MEDIUM5.5A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service ...
CVE-2020-4707MEDIUM5.4IBM API Connect 5.0.0.0 through 5.0.8.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2020-19305CRITICAL9.8An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when ...
CVE-2020-19304HIGH7.5An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory...
CVE-2020-19303HIGH7.8An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a ...
CVE-2020-19302CRITICAL9.8An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a websh...
CVE-2020-19301CRITICAL9.8A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a...
CVE-2020-26806HIGH8.8admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in r...
CVE-2020-26565HIGH7.5ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. Thi...
CVE-2020-26564MEDIUM6.5ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create ...
CVE-2020-26563MEDIUM6.1ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query st...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now