2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-21827HIGH7.8A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode...
CVE-2020-29205MEDIUM6.1XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via t...
CVE-2020-24993MEDIUM5.4There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visito...
CVE-2020-24992MEDIUM5.4There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an adm...
CVE-2020-21819HIGH8.8A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../programs/escape.c:51.
CVE-2020-21818HIGH8.8A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:48.
CVE-2020-21817MEDIUM6.5A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which cause...
CVE-2020-21816HIGH8.8A heab based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:46.
CVE-2020-21815MEDIUM6.5A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which caus...
CVE-2020-21814HIGH8.8A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97.
CVE-2020-21813HIGH7.8A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114.
CVE-2020-4670CRITICAL9.1IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, runnin...
CVE-2020-4669CRITICAL9.1IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listenin...
CVE-2020-13667MEDIUM5.3Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. ...
CVE-2020-16632MEDIUM5.4A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remot...
CVE-2020-27833HIGH7.1A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by us...
CVE-2020-24119HIGH7.1A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
CVE-2020-27769LOW3.3In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCor...
CVE-2020-17891MEDIUM6.1TP-Link Archer C1200 firmware version 1.13 Build 2018/01/24 rel.52299 EU has a XSS vulnerability allowing a remote attac...
CVE-2020-4985HIGH7.5IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameter...
CVE-2020-4811LOW2.4IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a privileged user to injec...
CVE-2020-23691CRITICAL9.8YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php.
CVE-2020-23689MEDIUM4.8In YFCMF v2.3.1, there is a stored XSS vulnerability in the comments section of the news page.
CVE-2020-18167MEDIUM4.8Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands int...
CVE-2020-18166CRITICAL9.8Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now