2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-21827 | HIGH | 7.8 | 1.0% | May 17, 2021 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode... |
| CVE-2020-29205 | MEDIUM | 6.1 | 1.5% | May 17, 2021 | XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via t... |
| CVE-2020-24993 | MEDIUM | 5.4 | 0.5% | May 17, 2021 | There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visito... |
| CVE-2020-24992 | MEDIUM | 5.4 | 0.5% | May 17, 2021 | There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an adm... |
| CVE-2020-21819 | HIGH | 8.8 | 1.2% | May 17, 2021 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../programs/escape.c:51. |
| CVE-2020-21818 | HIGH | 8.8 | 1.2% | May 17, 2021 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:48. |
| CVE-2020-21817 | MEDIUM | 6.5 | 0.9% | May 17, 2021 | A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which cause... |
| CVE-2020-21816 | HIGH | 8.8 | 1.2% | May 17, 2021 | A heab based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:46. |
| CVE-2020-21815 | MEDIUM | 6.5 | 0.9% | May 17, 2021 | A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which caus... |
| CVE-2020-21814 | HIGH | 8.8 | 1.2% | May 17, 2021 | A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97. |
| CVE-2020-21813 | HIGH | 7.8 | 1.0% | May 17, 2021 | A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114. |
| CVE-2020-4670 | CRITICAL | 9.1 | 2.5% | May 17, 2021 | IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, runnin... |
| CVE-2020-4669 | CRITICAL | 9.1 | 1.9% | May 17, 2021 | IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listenin... |
| CVE-2020-13667 | MEDIUM | 5.3 | 0.9% | May 17, 2021 | Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. ... |
| CVE-2020-16632 | MEDIUM | 5.4 | 0.5% | May 15, 2021 | A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remot... |
| CVE-2020-27833 | HIGH | 7.1 | 1.7% | May 14, 2021 | A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by us... |
| CVE-2020-24119 | HIGH | 7.1 | 1.1% | May 14, 2021 | A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect. |
| CVE-2020-27769 | LOW | 3.3 | 1.1% | May 14, 2021 | In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCor... |
| CVE-2020-17891 | MEDIUM | 6.1 | 1.2% | May 14, 2021 | TP-Link Archer C1200 firmware version 1.13 Build 2018/01/24 rel.52299 EU has a XSS vulnerability allowing a remote attac... |
| CVE-2020-4985 | HIGH | 7.5 | 1.0% | May 14, 2021 | IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameter... |
| CVE-2020-4811 | LOW | 2.4 | 0.7% | May 14, 2021 | IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a privileged user to injec... |
| CVE-2020-23691 | CRITICAL | 9.8 | 3.4% | May 14, 2021 | YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php. |
| CVE-2020-23689 | MEDIUM | 4.8 | 0.6% | May 14, 2021 | In YFCMF v2.3.1, there is a stored XSS vulnerability in the comments section of the news page. |
| CVE-2020-18167 | MEDIUM | 4.8 | 0.9% | May 14, 2021 | Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands int... |
| CVE-2020-18166 | CRITICAL | 9.8 | 1.7% | May 14, 2021 | Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now