2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-23036 | MEDIUM | 5.9 | 1.1% | Oct 22, 2021 | MEDIA NAVI Inc SMACom v1.2 was discovered to contain an insecure session validation vulnerability in the session handlin... |
| CVE-2020-8291 | MEDIUM | 6.1 | 0.6% | Oct 18, 2021 | A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks. |
| CVE-2020-19964 | MEDIUM | 6.5 | 0.6% | Oct 14, 2021 | A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new... |
| CVE-2020-19962 | MEDIUM | 5.4 | 0.6% | Oct 14, 2021 | A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.3... |
| CVE-2020-22679 | MEDIUM | 5.5 | 0.7% | Oct 12, 2021 | Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS)... |
| CVE-2020-22678 | MEDIUM | 5.5 | 0.7% | Oct 12, 2021 | An issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes function in av_parsers.c has a heap-base... |
| CVE-2020-22677 | MEDIUM | 5.5 | 0.7% | Oct 12, 2021 | An issue was discovered in gpac 0.8.0. The dump_data_hex function in box_dump.c has a heap-based buffer overflow which c... |
| CVE-2020-22675 | MEDIUM | 5.5 | 0.7% | Oct 12, 2021 | An issue was discovered in gpac 0.8.0. The GetGhostNum function in stbl_read.c has a heap-based buffer overflow which ca... |
| CVE-2020-22674 | MEDIUM | 5.5 | 0.7% | Oct 12, 2021 | An issue was discovered in gpac 0.8.0. An invalid memory dereference exists in the function FixTrackID located in isom_i... |
| CVE-2020-22673 | MEDIUM | 5.5 | 0.7% | Oct 12, 2021 | Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a... |
| CVE-2020-4654 | MEDIUM | 6.5 | 0.7% | Oct 8, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due ... |
| CVE-2020-21729 | MEDIUM | 5.4 | 0.6% | Oct 7, 2021 | JEECMS x1.1 contains a stored cross-site scripting (XSS) vulnerability in the component of /member-vipcenter.htm, which ... |
| CVE-2020-21658 | MEDIUM | 6.5 | 0.5% | Oct 6, 2021 | A Cross-Site Request Forgery (CSRF) in WDJA CMS v1.5.2 allows attackers to arbitrarily add administrator accounts via a ... |
| CVE-2020-21656 | MEDIUM | 5.4 | 0.4% | Oct 6, 2021 | XYHCMS v3.6 contains a stored cross-site scripting (XSS) vulnerability in the component xyhai.php?s=/Link/index. |
| CVE-2020-19003 | MEDIUM | 5.3 | 0.8% | Oct 6, 2021 | An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to ... |
| CVE-2020-15941 | MEDIUM | 5.4 | 1.1% | Oct 6, 2021 | A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authent... |
| CVE-2020-21506 | MEDIUM | 6.1 | 0.6% | Oct 5, 2021 | waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?m=Config&a=add... |
| CVE-2020-21505 | MEDIUM | 6.1 | 0.6% | Oct 5, 2021 | waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php/Link/addsave. |
| CVE-2020-21504 | MEDIUM | 6.1 | 0.6% | Oct 5, 2021 | waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?&m=Public&a=lo... |
| CVE-2020-21496 | MEDIUM | 6.1 | 0.7% | Oct 4, 2021 | A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers... |
| CVE-2020-21495 | MEDIUM | 6.1 | 0.7% | Oct 4, 2021 | A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers... |
| CVE-2020-21494 | MEDIUM | 6.1 | 0.7% | Oct 4, 2021 | A cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to e... |
| CVE-2020-21493 | MEDIUM | 5.3 | 1.0% | Oct 4, 2021 | An issue in the component route\user.php of Xiuno BBS v4.0.4 allows attackers to enumerate usernames. |
| CVE-2020-21434 | MEDIUM | 5.4 | 0.5% | Oct 4, 2021 | Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vuln... |
| CVE-2020-21431 | MEDIUM | 6.5 | 0.9% | Oct 4, 2021 | HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now