2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35437MEDIUM6.1Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the...
CVE-2020-35376HIGH7.5Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to...
CVE-2020-35349MEDIUM4.8Savsoft Quiz 5 is affected by: Cross Site Scripting (XSS) via field_title (aka a title on the custom fields page).
CVE-2020-35347MEDIUM6.5CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.
CVE-2020-35346MEDIUM4.8CXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script ...
CVE-2020-20412MEDIUM6.5lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds ...
CVE-2020-35388HIGH7.5rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in whi...
CVE-2020-35575CRITICAL9.8A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full adminis...
CVE-2020-29385MEDIUM5.5GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write...
CVE-2020-29172MEDIUM6.1A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via...
CVE-2020-27515MEDIUM6.1A Cross Site Scripting (XSS) vulnerability in Savsoft Quiz v5.0 allows remote attackers to inject arbitrary web script o...
CVE-2020-26766HIGH8.8A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login...
CVE-2020-25917HIGH8.8Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform,...
CVE-2020-35716HIGH7.5Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segment...
CVE-2020-35715HIGH8.8Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shel...
CVE-2020-35714HIGH8.8Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via gofor...
CVE-2020-35713CRITICAL9.8Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new passw...
CVE-2020-35712CRITICAL9.8Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
CVE-2020-35711HIGH7.5An issue has been discovered in the arc-swap crate before 0.4.8 (and 1.x before 1.1.0) for Rust. Use of arc_swap::access...
CVE-2020-35710MEDIUM5.3Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submissi...
CVE-2020-35709MEDIUM4.9bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../me...
CVE-2020-35708HIGH7.2phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Adminis...
CVE-2020-35707MEDIUM5.4Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.
CVE-2020-35706MEDIUM5.4Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen.
CVE-2020-35705MEDIUM5.4Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now