2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-23036MEDIUM5.9MEDIA NAVI Inc SMACom v1.2 was discovered to contain an insecure session validation vulnerability in the session handlin...
CVE-2020-8291MEDIUM6.1A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.
CVE-2020-19964MEDIUM6.5A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new...
CVE-2020-19962MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.3...
CVE-2020-22679MEDIUM5.5Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS)...
CVE-2020-22678MEDIUM5.5An issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes function in av_parsers.c has a heap-base...
CVE-2020-22677MEDIUM5.5An issue was discovered in gpac 0.8.0. The dump_data_hex function in box_dump.c has a heap-based buffer overflow which c...
CVE-2020-22675MEDIUM5.5An issue was discovered in gpac 0.8.0. The GetGhostNum function in stbl_read.c has a heap-based buffer overflow which ca...
CVE-2020-22674MEDIUM5.5An issue was discovered in gpac 0.8.0. An invalid memory dereference exists in the function FixTrackID located in isom_i...
CVE-2020-22673MEDIUM5.5Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a...
CVE-2020-4654MEDIUM6.5IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due ...
CVE-2020-21729MEDIUM5.4JEECMS x1.1 contains a stored cross-site scripting (XSS) vulnerability in the component of /member-vipcenter.htm, which ...
CVE-2020-21658MEDIUM6.5A Cross-Site Request Forgery (CSRF) in WDJA CMS v1.5.2 allows attackers to arbitrarily add administrator accounts via a ...
CVE-2020-21656MEDIUM5.4XYHCMS v3.6 contains a stored cross-site scripting (XSS) vulnerability in the component xyhai.php?s=/Link/index.
CVE-2020-19003MEDIUM5.3An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to ...
CVE-2020-15941MEDIUM5.4A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authent...
CVE-2020-21506MEDIUM6.1waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?m=Config&a=add...
CVE-2020-21505MEDIUM6.1waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php/Link/addsave.
CVE-2020-21504MEDIUM6.1waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?&m=Public&a=lo...
CVE-2020-21496MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers...
CVE-2020-21495MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers...
CVE-2020-21494MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to e...
CVE-2020-21493MEDIUM5.3An issue in the component route\user.php of Xiuno BBS v4.0.4 allows attackers to enumerate usernames.
CVE-2020-21434MEDIUM5.4Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vuln...
CVE-2020-21431MEDIUM6.5HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now