2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35437 | MEDIUM | 6.1 | 3.0% | Dec 26, 2020 | Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the... |
| CVE-2020-35376 | HIGH | 7.5 | 2.1% | Dec 26, 2020 | Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to... |
| CVE-2020-35349 | MEDIUM | 4.8 | 0.6% | Dec 26, 2020 | Savsoft Quiz 5 is affected by: Cross Site Scripting (XSS) via field_title (aka a title on the custom fields page). |
| CVE-2020-35347 | MEDIUM | 6.5 | 0.4% | Dec 26, 2020 | CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add. |
| CVE-2020-35346 | MEDIUM | 4.8 | 0.7% | Dec 26, 2020 | CXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script ... |
| CVE-2020-20412 | MEDIUM | 6.5 | 1.0% | Dec 26, 2020 | lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds ... |
| CVE-2020-35388 | HIGH | 7.5 | 1.5% | Dec 26, 2020 | rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in whi... |
| CVE-2020-35575 | CRITICAL | 9.8 | 7.6% | Dec 26, 2020 | A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full adminis... |
| CVE-2020-29385 | MEDIUM | 5.5 | 1.5% | Dec 26, 2020 | GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write... |
| CVE-2020-29172 | MEDIUM | 6.1 | 0.9% | Dec 26, 2020 | A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via... |
| CVE-2020-27515 | MEDIUM | 6.1 | 1.3% | Dec 26, 2020 | A Cross Site Scripting (XSS) vulnerability in Savsoft Quiz v5.0 allows remote attackers to inject arbitrary web script o... |
| CVE-2020-26766 | HIGH | 8.8 | 0.6% | Dec 26, 2020 | A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login... |
| CVE-2020-25917 | HIGH | 8.8 | 1.2% | Dec 26, 2020 | Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform,... |
| CVE-2020-35716 | HIGH | 7.5 | 3.9% | Dec 26, 2020 | Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segment... |
| CVE-2020-35715 | HIGH | 8.8 | 3.7% | Dec 26, 2020 | Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shel... |
| CVE-2020-35714 | HIGH | 8.8 | 2.7% | Dec 26, 2020 | Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via gofor... |
| CVE-2020-35713 | CRITICAL | 9.8 | 32.7% | Dec 26, 2020 | Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new passw... |
| CVE-2020-35712 | CRITICAL | 9.8 | 1.6% | Dec 26, 2020 | Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations. |
| CVE-2020-35711 | HIGH | 7.5 | 1.6% | Dec 25, 2020 | An issue has been discovered in the arc-swap crate before 0.4.8 (and 1.x before 1.1.0) for Rust. Use of arc_swap::access... |
| CVE-2020-35710 | MEDIUM | 5.3 | 1.7% | Dec 25, 2020 | Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submissi... |
| CVE-2020-35709 | MEDIUM | 4.9 | 1.1% | Dec 25, 2020 | bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../me... |
| CVE-2020-35708 | HIGH | 7.2 | 1.5% | Dec 25, 2020 | phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Adminis... |
| CVE-2020-35707 | MEDIUM | 5.4 | 0.6% | Dec 25, 2020 | Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen. |
| CVE-2020-35706 | MEDIUM | 5.4 | 0.6% | Dec 25, 2020 | Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen. |
| CVE-2020-35705 | MEDIUM | 5.4 | 0.6% | Dec 25, 2020 | Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now